问题可能出现在 AccessPolicy 中。检查 AccessPolicy 中的 PolicyDocument,"Effect" 和 "Action" 是否正确,并确保 "Resource" 引用了正确的资源 ARN。此外,还需确保 Cognito 身份池 ID、用户池 ID 和角色名称均正确。
示例代码:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"es:*"
],
"Resource": "arn:aws:es:us-west-2:123456789012:domain/my-domain/*",
"Condition": {
"Bool": {
"aws:SecureTransport": "true"
}
}
},
{
"Effect": "Allow",
"Action": [
"cognito-identity:*"
],
"Resource": [
"arn:aws:cognito-identity:us-west-2:123456789012:identitypool/us-west-2:11111111-2222-3333-4444-555555555555",
"arn:aws:cognito-idp:us-west-2:123456789012:userpool/us-west-2_abcdefghi",
"arn:aws:iam::123456789012:role/Cognito-MyTestRole"
]
}
]
}
上一篇:AWSOceaniaRegion