Cognito Auth
A reusable Go package for AWS Cognito authentication and authorization with Echo framework using PKCE flow.
Features
- Complete OAuth 2.0 PKCE flow for AWS Cognito
- JWT token validation and verification
- Route-based authorization using Cognito user groups
- Middleware for token handling
- Cookie-based token storage
- Default home page with authentication status
- Simple integration with Echo framework
Installation
go get github.com/yourusername/cognitoauth
Configuration
The package reads configuration from environment variables:
COGNITO_CLIENT_ID: Your AWS Cognito App Client IDCOGNITO_CLIENT_SECRET: Your AWS Cognito App Client Secret (optional for public clients)COGNITO_USER_POOL_ID: Your AWS Cognito User Pool IDCOGNITO_DOMAIN: Your AWS Cognito domainAWS_REGION: AWS region where your Cognito User Pool is locatedDEBUG: Set to "true" for debug logging
Optional path configuration:
COGNITO_LOGIN_PATH: Path for login endpoint (default: "/login")COGNITO_CALLBACK_PATH: Path for OAuth callback (default: "/