Create an Amazon Cognito OAuthProvider (via OIDC discovery)
Source:R/providers__research_enterprise.R
oauth_provider_cognito.RdConfigure OIDC login for an Amazon Cognito user pool. Register an app client
with the authorization code grant, configure a user pool login domain, and
pass the app credentials to oauth_client() with the enabled OIDC scopes.
Arguments
- issuer
Exact user pool issuer URL from AWS, for example
"https://cognito-idp.eu-west-1.amazonaws.com/eu-west-1_Example".- name
Optional provider name (default
"cognito").- token_auth_style
Authentication style for token requests: "header" (client_secret_basic), "body" (client_secret_post), or "public" (public client; send
client_idonly). The alias"none"is also accepted for"public". If NULL (default), it is inferred conservatively from discovery:"header"(client_secret_basic) is preferred, followed by"body"(client_secret_post), then"public"ifnoneis advertised and PKCE is enabled. Settoken_auth_style = "public"explicitly for a public client registration. JWT methods ("client_secret_jwt","private_key_jwt") and mTLS methods ("tls_client_auth","self_signed_tls_client_auth") must be selected explicitly. Seeoauth_provider()for the supported methods and their credentials.
Value
OAuthProvider object configured for a Cognito user pool.
Details
Use the exact user pool issuer, not the managed-login or custom domain.
Discovery obtains authorization, token, and UserInfo URLs on that login
domain while retaining the pool issuer for ID token validation. Both the
original cognito-idp and updated issuer-cognito-idp issuer forms are
supported, as are AWS partition-specific hostnames. No AWS credentials
are needed for discovery.
See Cognito endpoints.