AWS Cognito Custom Auth Flow with Email TOTP: how to remember device and set the expiration time of the One Time Password?

Viewed 424

I have followed this AWS blog to implement the Custom Authentication Flow for my website with Email TOTP (Time based One Time Password) as a MFA: https://aws.amazon.com/blogs/mobile/extending-amazon-cognito-with-email-otp-for-2fa-using-amazon-ses/

Basically it explains that on Cognito, how to use the CUSTOM_CHALLENGE and 3 lambda function to:

  1. Define custom auth challenge
  2. Create custom auth challenge code and send to user's email address through AWS SES;
  3. Verify that the verification code the user submitted is correct;

such that we can achieve the same effect as text-message based MFA, except that the code is sent as an email instead of text-message on the phone.

Note that this is very different from the "MFA" section on the Cognito User Pool settings:

enter image description here

The above MFA is for text-message on the phone.

After following the blog tutorial, I got things to work nicely.

However I have 2 questions and I couldn't find a solution online:

  1. How can I set the expiration time of the One Time Password sent to user's email? \

    I am sure there is an expiration time and I believe it is 10 minutes, but the Documentation is nowhere to be found.

  2. How can I allow cognito to remember the device such that Email TOTP as a 2nd Factor is only required when the user tried to sign in from a different device from previous device?

For the text-message based MFA (or the "real" MFA) on Cognito Settings, this is easily achieved by simply enabling on the "Device" section:

Do you want to use a remembered device to suppress the second factor during multi-factor authentication (MFA)?

enter image description here

However, how can I do this for the method that implements Email OTP for 2FA?

0 Answers
Related