Skip to content

Commit e431f47

Browse files
authored
chore: kickoff release
2 parents 33cc3d3 + af96232 commit e431f47

6 files changed

Lines changed: 40 additions & 14 deletions

File tree

AmplifyPlugins/Auth/Sources/AWSCognitoAuthPlugin/Actions/SignIn/DeviceSRPAuth/VerifyDevicePasswordSRP.swift

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -40,8 +40,12 @@ struct VerifyDevicePasswordSRP: Action {
4040
credentialStoreClient: environment.authEnvironment().credentialsClient
4141
)
4242

43+
// Read with the username the caller signed in with — `ConfirmDevice` writes the
44+
// metadata under `inputUsername` (here `stateData.username`). `username` is
45+
// `parameters["USERNAME"]`, the sub echoed by Cognito on alias pools, and is still the
46+
// correct value to send back in the request below.
4347
let deviceMetadata = await DeviceMetadataHelper.getDeviceMetadata(
44-
for: username,
48+
for: inputUsername,
4549
with: environment
4650
)
4751
guard

AmplifyPlugins/Auth/Sources/AWSCognitoAuthPlugin/Actions/SignIn/SRPAuth/VerifyPasswordSRP.swift

Lines changed: 11 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -53,8 +53,13 @@ struct VerifyPasswordSRP: Action {
5353
credentialStoreClient: environment.authEnvironment().credentialsClient
5454
)
5555

56+
// Device metadata is stored under the username the caller signed in with
57+
// (`ConfirmDevice` uses `signedInData.inputUsername`), so it must be read back with
58+
// the same value. `username` here is `parameters["USERNAME"]`, which for pools with
59+
// alias sign-in is the sub — looking metadata up with it never matches what was
60+
// written, so DEVICE_KEY would be omitted and every sign-in would register a new device.
5661
deviceMetadata = await DeviceMetadataHelper.getDeviceMetadata(
57-
for: username,
62+
for: inputUsername,
5863
with: environment
5964
)
6065
let signature = try signature(
@@ -100,8 +105,11 @@ struct VerifyPasswordSRP: Action {
100105
await dispatcher.send(event)
101106
} catch let error where deviceNotFound(error: error, deviceMetadata: deviceMetadata) {
102107
logVerbose("\(#fileID) Received device not found \(error)", environment: environment)
103-
// Remove the saved device details and retry password verify
104-
await DeviceMetadataHelper.removeDeviceMetaData(for: username, with: environment)
108+
// Remove the saved device details and retry password verify. This must use the same
109+
// value the metadata was read with above — deleting under `username` (the echoed sub)
110+
// leaves the real entry in place, so the retry re-reads the same stale device key,
111+
// Cognito rejects it again, and sign-in loops here indefinitely.
112+
await DeviceMetadataHelper.removeDeviceMetaData(for: inputUsername, with: environment)
105113
let event = SignInEvent(eventType: .retryRespondPasswordVerifier(stateData, authResponse, clientMetadata))
106114
logVerbose(
107115
"\(#fileID) Sending event \(event)",

AmplifyPlugins/Auth/Sources/AWSCognitoAuthPlugin/Actions/SignIn/VerifySignInChallenge.swift

Lines changed: 12 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -75,8 +75,11 @@ struct VerifySignInChallenge: Action {
7575
credentialStoreClient: environment.authEnvironment().credentialsClient
7676
)
7777

78+
// Read with the username the caller signed in with — `ConfirmDevice` writes the
79+
// metadata under `inputUsername`, and `challenge.username` is the value Cognito
80+
// returned (the sub, for pools using alias sign-in).
7881
deviceMetadata = await DeviceMetadataHelper.getDeviceMetadata(
79-
for: username,
82+
for: challenge.inputUsername ?? username,
8083
with: environment
8184
)
8285

@@ -107,8 +110,13 @@ struct VerifySignInChallenge: Action {
107110
await dispatcher.send(responseEvent)
108111
} catch let error where deviceNotFound(error: error, deviceMetadata: deviceMetadata) {
109112
logVerbose("\(#fileID) Received device not found \(error)", environment: environment)
110-
// Remove the saved device details and retry verify challenge
111-
await DeviceMetadataHelper.removeDeviceMetaData(for: username, with: environment)
113+
// Remove the saved device details and retry verify challenge. Must match the value the
114+
// metadata was read with above — deleting under `username` (the echoed sub) leaves the
115+
// real entry in place and the retry loops on the same stale device key.
116+
await DeviceMetadataHelper.removeDeviceMetaData(
117+
for: challenge.inputUsername ?? username,
118+
with: environment
119+
)
112120
let event = SignInChallengeEvent(
113121
eventType: .retryVerifyChallengeAnswer(confirmSignEventData, currentSignInStep)
114122
)
@@ -139,7 +147,7 @@ struct VerifySignInChallenge: Action {
139147
) async throws {
140148

141149
let newDeviceMetadata = await DeviceMetadataHelper.getDeviceMetadata(
142-
for: username,
150+
for: challenge.inputUsername ?? username,
143151
with: environment
144152
)
145153
if challenge.challenge == .password {

AmplifyPlugins/Auth/Sources/AWSCognitoAuthPlugin/Support/Helpers/UserPoolSignInHelper.swift

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -146,7 +146,13 @@ struct UserPoolSignInHelper: DefaultLogger {
146146
eventType: .respondPasswordVerifier(srpStateData, response, [:])
147147
)
148148
case .deviceSrpAuth:
149-
return SignInEvent(eventType: .initiateDeviceSRP(username, response))
149+
// Carry the caller's `inputUsername` into the device SRP flow. It has to look
150+
// the stored device metadata back up, and that's keyed on the username the
151+
// caller signed in with (see `ConfirmDevice`). `username` here is the value
152+
// Cognito echoed — the sub, on pools with alias sign-in — so using it makes the
153+
// lookup miss and the request omits DEVICE_KEY, which Cognito rejects with
154+
// "Missing required parameter DEVICE_KEY".
155+
return SignInEvent(eventType: .initiateDeviceSRP(inputUsername ?? username, response))
150156
case .webAuthn:
151157
let signInData = WebAuthnSignInData(
152158
username: username,

Package.resolved

Lines changed: 4 additions & 4 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

Package.swift

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ let platforms: [SupportedPlatform] = [
99
.watchOS(.v9)
1010
]
1111
let dependencies: [Package.Dependency] = [
12-
.package(url: "https://github.com/awslabs/aws-sdk-swift", exact: "1.7.27"),
12+
.package(url: "https://github.com/awslabs/aws-sdk-swift", exact: "1.7.53"),
1313
.package(url: "https://github.com/stephencelis/SQLite.swift.git", exact: "0.15.4"),
1414
.package(url: "https://github.com/mattgallagher/CwlPreconditionTesting.git", from: "2.1.0"),
1515
.package(url: "https://github.com/aws-amplify/amplify-swift-utils-notifications.git", from: "1.1.0")

0 commit comments

Comments
 (0)