I am looking into using AWS-Cognito as a means to manage and authenticate users. I do not want to use aws api-gateway or any of their other services really. It seems though you can only create roles or policies if they are related to some other aws service. I'd like to have these custom roles or policies on the user's id token returned from Cognito. Is it possible to create these custom roles or policies or am I restricted to only roles and policies related to amazon services? I have found tried the Create your own policy, but it throws an error if it doesn't match a specific action or resource known to aws services. Thanks.
Creating custom Roles and Policies
1.2k Views Asked by Trevor At
1
There are 1 best solutions below
Related Questions in AMAZON-COGNITO
- Getting cross client id token for AWS from Google Sign-In SDK
- AWS Cognito: Access to Identity is forbidden when calling getOpenIdToken()
- how to use AWS cognito with custom authentication to create temporary s3 upload security token
- How to merge AWS Cognito identities
- Put file on S3 with AWS SDK 2 & Cognito for unauth users using iOS SDK 2
- Specifying IAM roles for permissions in AWS S3
- obtaining AWS credentials using cognito in python boto
- AWS.config.credentials are null between page requests
- AWS Cognito Invalid login token error with my token from Developer authentication
- AWS Custom Authorizer with request parameters
- Register a New User with the Mobile SDK for Android on AWS Cognito
- adding a record to existing aws cognito dataset
- Thread 1: Signal SIGABRT (Could not cast value of type to 'SignInViewController' to 'AWSCognitoIdentityPasswordAuthentication')
- Examples of Ruby on rails + aws congnito
- Android AWS Cognito UserPool globalSignout not working when user is signed in from multiple devices
Related Questions in AWS-IOS
- Cognito isSignedIn latency issue after successful login
- Query AWS Dynamo Db Data base using an Array
- Creating custom Roles and Policies
- Error Running Amplify Push after Running Amplify Auth Update
- How to subscribe multiple topics in "AWSIoT" iOS SDK?
- Amazon Cognito + iOS Swift - Custom UI
- AmazonClientManager - Issue with resumeSessionWithCompletionHandler in AWSCognito GPlus Login iOS
- AWS Cognito synchronize issue with AWSCognitoDataset iOS
- how to facebook user authentic in AWSAmazon identity pool id
- Is it possible to prepolulate an AWS AppSync iOS client?
- AWS S3 : iOS SDK - AWSContentDownloadTypeIfNewerExists not working
- iOS AWS API Gateway : Unauthenticated access is not supported for this identity pool
- aws ios sdk - Issue downloading images from s3
- AWS Lambda - The role defined for the function cannot be assumed by Lambda
Trending Questions
- UIImageView Frame Doesn't Reflect Constraints
- Is it possible to use adb commands to click on a view by finding its ID?
- How to create a new web character symbol recognizable by html/javascript?
- Why isn't my CSS3 animation smooth in Google Chrome (but very smooth on other browsers)?
- Heap Gives Page Fault
- Connect ffmpeg to Visual Studio 2008
- Both Object- and ValueAnimator jumps when Duration is set above API LvL 24
- How to avoid default initialization of objects in std::vector?
- second argument of the command line arguments in a format other than char** argv or char* argv[]
- How to improve efficiency of algorithm which generates next lexicographic permutation?
- Navigating to the another actvity app getting crash in android
- How to read the particular message format in android and store in sqlite database?
- Resetting inventory status after order is cancelled
- Efficiently compute powers of X in SSE/AVX
- Insert into an external database using ajax and php : POST 500 (Internal Server Error)
Popular Questions
- How do I undo the most recent local commits in Git?
- How can I remove a specific item from an array in JavaScript?
- How do I delete a Git branch locally and remotely?
- Find all files containing a specific text (string) on Linux?
- How do I revert a Git repository to a previous commit?
- How do I create an HTML button that acts like a link?
- How do I check out a remote Git branch?
- How do I force "git pull" to overwrite local files?
- How do I list all files of a directory?
- How to check whether a string contains a substring in JavaScript?
- How do I redirect to another webpage?
- How can I iterate over rows in a Pandas DataFrame?
- How do I convert a String to an int in Java?
- Does Python have a string 'contains' substring method?
- How do I check if a string contains a specific word?
You can use Cognito User Pools to authenticate your users. Then you can call STS to issue temporary credentials based upon your own rules (policies). Look into examples using assumeRole().
If you want an integrated / managed service then use Cognito Federated Identities for authorization and Cognito Users Pools or Google, etc. for authentication.
Sort of confusing, but think of Cognito User Pools (or Facebook, etc.) as the Identity Provider and Cognito Federated Users as the Permissions broker.