I'm struggling with obtaining STS token from Cognito Identity via authenticated Cognito User Pool. I used the react-oauth2-pkce library to add Cognito hosted UI to authenticate in react spa. I'm able to get access/id/refresh tokens from Cognito User Pool. I configured Cognito Federated Identity for that User Pool but I'm unable to get the AWS creds via STS.
const authTokens = authService.getAuthTokens();
useEffect(() => {
const creds = fromWebToken({
roleArn:
"arn:aws:iam::<account_id>:role/my-assume-role-with-web-identity",
clientConfig: { region: "<region>" },
webIdentityToken: authTokens.id_token,
});
const cb = async () => await creds();
console.log("creds", cb());
}, [authTokens]);
When I executed this piece of code I'm getting AccessDenied
POST https://sts.eu-west-1.amazonaws.com/ 403 (Forbidden)
AccessDenied: Not authorized to perform sts:AssumeRoleWithWebIdentity
The my-assume-role-with-web-identity has the following policy set up
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"Federated": "cognito-identity.amazonaws.com"
},
"Action": "sts:AssumeRoleWithWebIdentity",
"Condition": {
"StringEquals": {
"cognito-identity.amazonaws.com:aud": "<cognito identity pool id>"
}
}
}
]
}