Access to cognito identity from cognito user pool via web token

Viewed 83

I'm struggling with obtaining STS token from Cognito Identity via authenticated Cognito User Pool. I used the react-oauth2-pkce library to add Cognito hosted UI to authenticate in react spa. I'm able to get access/id/refresh tokens from Cognito User Pool. I configured Cognito Federated Identity for that User Pool but I'm unable to get the AWS creds via STS.

const authTokens = authService.getAuthTokens();

useEffect(() => {
  const creds = fromWebToken({
    roleArn:
      "arn:aws:iam::<account_id>:role/my-assume-role-with-web-identity",
    clientConfig: { region: "<region>" },
    webIdentityToken: authTokens.id_token,
  });
  const cb = async () => await creds();
  console.log("creds", cb());
}, [authTokens]);

When I executed this piece of code I'm getting AccessDenied

POST https://sts.eu-west-1.amazonaws.com/ 403 (Forbidden)
AccessDenied: Not authorized to perform sts:AssumeRoleWithWebIdentity

The my-assume-role-with-web-identity has the following policy set up

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": {
        "Federated": "cognito-identity.amazonaws.com"
      },
      "Action": "sts:AssumeRoleWithWebIdentity",
      "Condition": {
        "StringEquals": {
          "cognito-identity.amazonaws.com:aud": "<cognito identity pool id>"
        }
      }
    }
  ]
}
0 Answers
Related