I have followed this AWS blog to implement the Custom Authentication Flow for my website with Email TOTP (Time based One Time Password) as a MFA: https://aws.amazon.com/blogs/mobile/extending-amazon-cognito-with-email-otp-for-2fa-using-amazon-ses/
Basically it explains that on Cognito, how to use the CUSTOM_CHALLENGE and 3 lambda function to:
- Define custom auth challenge
- Create custom auth challenge code and send to user's email address through AWS SES;
- Verify that the verification code the user submitted is correct;
such that we can achieve the same effect as text-message based MFA, except that the code is sent as an email instead of text-message on the phone.
Note that this is very different from the "MFA" section on the Cognito User Pool settings:
The above MFA is for text-message on the phone.
After following the blog tutorial, I got things to work nicely.
However I have 2 questions and I couldn't find a solution online:
How can I set the expiration time of the One Time Password sent to user's email? \
I am sure there is an expiration time and I believe it is 10 minutes, but the Documentation is nowhere to be found.
How can I allow cognito to remember the device such that Email TOTP as a 2nd Factor is only required when the user tried to sign in from a different device from previous device?
For the text-message based MFA (or the "real" MFA) on Cognito Settings, this is easily achieved by simply enabling on the "Device" section:
Do you want to use a remembered device to suppress the second factor during multi-factor authentication (MFA)?
However, how can I do this for the method that implements Email OTP for 2FA?

