Is there a way to have Cognito User Pools forwarding certain information to Custom OIDC providers as part of the /authorize request?
I am using Auth0 as our AuthN/AuthZ service. One of my clients is extending their Cognito Identity Pool to connect to this Auth0 tenant.
That works pretty well, however, due to certain business rules, I need to prevent having different users on Cognito User Pool to either create many accounts on Auth0 or log in with different accounts.
I must ensure there is one and only one Cognito User linked to Auth0 user.
We already had that logic in place for other providers via the id_token_hint and use an Auth0 rule to grab the id_token_hint and validate certain information that the client must include.
The problem we are facing is that Cognito does not seem to have a way to provide context to OIDC providers, in other words, Cognito does not forward the id_token_hint to Auth0. Indeed, Cognito does not forward anything to the OIDC provider.
UPDATE
On the validate step, I need to ensure that User 1234 from Contoso.com is linked to only one account on Auth0 in order to prevent fraud (there is a KYC process s part of the registration).
So, in order to proceed with the payment, Contoso must make an authenticated request to the payment provider, who under certain conditions might not allow guest payment and forces the user to authenticate.
The Payment provider uses Cognito that is connected to different OIDC providers, depending upon the client application (in this case Contoso) it redirects users to authenticate against one provider or another. Very important here is that there can be many third-party apps redirected to Auth0.
So, from Auth0 perspective, I need to have certain context of where the user is coming from (Contoso in this example) just to ensure that:
- User 1234 at Contoso is not operating under more than one and only one account on Auth0 side
- There is no another Auth0 account already linked to user 1234 at Contoso.
Due to some legal regulations, I need to prevent users from logging in if the above rules are not satisfied.
id_token_hint
The id_token_hint is part of the OIDC standard and it is a common way to provide some context to the OIDC service. The idea is to keep the solution as tied to the OIDC standard as possible.
For example, Azure AD and Auth0 support that field, and due to their respective designs you can run custom business logic and read the id_token_hint.
Some providers such as Auth0 forwards any extra parameters used in the Authorize URL.
Is there a way to have Cognito forwarding parameters to the downstream OIDC provider?
