Switching unauthenticated users to authenticated users
Amazon Cognito identity pools support both authenticated and unauthenticated users. Unauthenticated users receive access to your AWS resources even if they aren't logged in with any of your identity providers (IdPs). This degree of access is useful to display content to users before they log in. Each unauthenticated user has a unique identity in the identity pool, even though they haven't been individually logged in and authenticated.
This section describes the case where your user chooses to switch from logging in with an unauthenticated identity to using an authenticated identity.
Android
Users can log in to your application as unauthenticated guests. Eventually they might decide to log in using one of the supported IdPs. Amazon Cognito makes sure that an old identity retains the same unique identifier as the new one, and that the profile data is merged automatically.
Your application is informed of a profile merge through the
IdentityChangedListener interface. Implement the identityChanged
method in the interface to receive these messages:
@override public void identityChanged(String oldIdentityId, String newIdentityId) { // handle the change }
iOS - objective-C
Users can log in to your application as unauthenticated guests. Eventually they might decide to log in using one of the supported IdPs. Amazon Cognito makes sure that an old identity retains the same unique identifier as the new one, and that the profile data is merged automatically.
NSNotificationCenter informs your application of a profile merge:
[[NSNotificationCenter defaultCenter] addObserver:self selector:@selector(identityIdDidChange:) name:AWSCognitoIdentityIdChangedNotification object:nil]; -(void)identityDidChange:(NSNotification*)notification { NSDictionary *userInfo = notification.userInfo; NSLog(@"identity changed from %@ to %@", [userInfo objectForKey:AWSCognitoNotificationPreviousId], [userInfo objectForKey:AWSCognitoNotificationNewId]); }
iOS - swift
Users can log in to your application as unauthenticated guests. Eventually they might decide to log in using one of the supported IdPs. Amazon Cognito makes sure that an old identity retains the same unique identifier as the new one, and that the profile data is merged automatically.
NSNotificationCenter informs your application of a profile merge:
[NSNotificationCenter.defaultCenter().addObserver(observer: self selector:"identityDidChange" name:AWSCognitoIdentityIdChangedNotification object:nil) func identityDidChange(notification: NSNotification!) { if let userInfo = notification.userInfo as? [String: AnyObject] { print("identity changed from: \(userInfo[AWSCognitoNotificationPreviousId]) to: \(userInfo[AWSCognitoNotificationNewId])") } }
JavaScript
Initially unauthenticated user
Users typically start with the unauthenticated role. For this role, you create a
fromCognitoIdentityPool credentials provider without a logins
property and attach it to your service clients. In this case, your default configuration
might look like the following:
import { fromCognitoIdentityPool } from "@aws-sdk/credential-providers"; // Create a credentials provider without a logins map for the unauthenticated role. const region = "us-east-1"; const credentials = fromCognitoIdentityPool({ identityPoolId: "us-east-1:1699ebc0-7900-4099-b910-2df94f52a030", clientConfig: { region } }); // Attach the provider to each service client that needs credentials. const client = new SomeServiceClient({ region, credentials });
Switch to authenticated user
When an unauthenticated user logs in to an IdP and you have a token, you can switch the
user from unauthenticated to authenticated by calling a custom function that creates a new
fromCognitoIdentityPool provider with the logins map that
contains the token:
// Called when an identity provider has a token for a logged in user function userLoggedIn(providerName, token) { // Re-create the provider with a logins map to switch to the authenticated role. const credentials = fromCognitoIdentityPool({ identityPoolId: "us-east-1:1699ebc0-7900-4099-b910-2df94f52a030", logins: { [providerName]: token }, clientConfig: { region } }); // Re-create any service clients so they pick up the new credentials. // SomeServiceClient is a placeholder: import the client for the service you're calling // (for example, S3Client from @aws-sdk/client-s3). const client = new SomeServiceClient({ region, credentials }); }
Because the fromCognitoIdentityPool provider is attached directly to each
service client, switching from the unauthenticated to the authenticated role means creating
a new provider with the logins map and passing it to any service clients that
you create afterward. Unlike the AWS SDK for JavaScript v2, the v3 SDK doesn't use a
global configuration object, so there are no shared credentials to reset.
For more information about the fromCognitoIdentityPool provider, see
AWS SDK for JavaScript v3 credential providers
Unity
Users can log in to your application as unauthenticated guests. Eventually they might decide to log in using one of the supported IdPs. Amazon Cognito makes sure that an old identity retains the same unique identifier as the new one, and that the profile data is merged automatically.
You can subscribe to the IdentityChangedEvent to be notified of profile
merges:
credentialsProvider.IdentityChangedEvent += delegate(object sender, CognitoAWSCredentials.IdentityChangedArgs e) { // handle the change Debug.log("Identity changed from " + e.OldIdentityId + " to " + e.NewIdentityId); };
Xamarin
Users can log in to your application as unauthenticated guests. Eventually they might decide to log in using one of the supported IdPs. Amazon Cognito makes sure that an old identity retains the same unique identifier as the new one, and that the profile data is merged automatically.
credentialsProvider.IdentityChangedEvent += delegate(object sender, CognitoAWSCredentials.IdentityChangedArgs e){ // handle the change Console.WriteLine("Identity changed from " + e.OldIdentityId + " to " + e.NewIdentityId); };