No video

AWS re:Invent 2017: [REPEAT] Serverless Authentication and Authorization: Identity M (SRV403-R)

  Рет қаралды 39,476

Amazon Web Services

Amazon Web Services

Күн бұрын

Пікірлер: 13
@VladimirOdessit
@VladimirOdessit 6 жыл бұрын
The app that we referenced during the talk: github.com/awslabs/aws-serverless-auth-reference-app Here's a sample single-page web-app written in Angular using Cognito and running on S3 (completely serverless): github.com/awslabs/aws-cognito-angular-quickstart Serverless Photo Recognition using most of the services we talked about, in addition to Amazon Rekognition: github.com/awslabs/serverless-photo-recognition Blog post: aws.amazon.com/blogs/ai/use-amazon-rekognition-to-build-an-end-to-end-serverless-photo-recognition-system/
@danielpapukchiev3754
@danielpapukchiev3754 6 жыл бұрын
Hello, we are using Cognito Federated Identities for Facebook and Google auth and Cognito Userpools for username/password flows. Our back-end is a serverless API with API Gateway. To protect it we wanted to use aws_iam authorizer but we reached a problem. To refresh aws keys with Cognito Federated Identities we have to supply the original Facebook/Google/Cognito tokens which also expire in a short period of time. How would a user coming from Facebook for example refresh his/hers AWS keys given from Cognito federated identities? In the end we decided to issue our own JWT tokens with refresh tokens via DynamoDB + custom lambda authorizers which validate those tokens, so all users go trough the same refresh flow apposed to using each identity provider refresh mechanism in the front end.
@VladimirOdessit
@VladimirOdessit 6 жыл бұрын
Take a look at this documentation: docs.aws.amazon.com/cognito/latest/developerguide/cognito-identity.html
@NS38845
@NS38845 6 жыл бұрын
I like how you numbered this 403
@VladimirOdessit
@VladimirOdessit 6 жыл бұрын
Good catch :)
@gummibare
@gummibare 6 жыл бұрын
Why is it that AWS passes the ID token to retrieve credentials from Federated Identities? Specifically at 9:50. Isn't Access Token the ideal token to use in this case, since it twas specifically meant for providing access to APIs?
@michaelchambers236
@michaelchambers236 6 жыл бұрын
Thank you both. Great presentation and very helpful!
@gireeshkumarmn2796
@gireeshkumarmn2796 5 жыл бұрын
Awesome! content and the best one to get started with cognito.
@VladimirOdessit
@VladimirOdessit 4 жыл бұрын
Glad to hear it :)
@elritualk
@elritualk 5 жыл бұрын
Hi, first thanks for this overview. I have a question: User Pool -> Federation cost money based on MAU and Federated Identity is free no matter what MAU you have?
@selimcse98
@selimcse98 5 жыл бұрын
Can you please share the application source code?
@hoangedward
@hoangedward 5 жыл бұрын
Mohammad Selim Miah at the end of video
AWS re:Invent 2017: Soup to Nuts: Identity Federation for AWS (SID344)
55:06
Amazon Web Services
Рет қаралды 19 М.
Magic trick 🪄😁
00:13
Andrey Grechka
Рет қаралды 45 МЛН
Son ❤️ #shorts by Leisi Show
00:41
Leisi Show
Рет қаралды 10 МЛН
Harley Quinn's revenge plan!!!#Harley Quinn #joker
00:59
Harley Quinn with the Joker
Рет қаралды 24 МЛН
My Cheetos🍕PIZZA #cooking #shorts
00:43
BANKII
Рет қаралды 27 МЛН
lofi hip hop radio 📚 - beats to relax/study to
Lofi Girl
Рет қаралды 19 М.
AWS re:Invent 2017: Deep Dive on AWS CloudFormation (DEV317)
1:00:01
Amazon Web Services
Рет қаралды 54 М.
AWS re:Invent 2017: [REPEAT] Which Database to Use When? (DAT310-R)
1:02:54
Amazon Web Services
Рет қаралды 38 М.
Magic trick 🪄😁
00:13
Andrey Grechka
Рет қаралды 45 МЛН