Cognito user pools now support a flag that prevents Cognito from raising errors that can be used to verify the existence of a user. This flag is currently set to legacy/false. It should be set to true to improve the security of application from fishing attacks. Till now, i couldn't find any key to work on that.
There is note from aws that:
After January 1st 2020, the value of PreventUserExistenceErrors will default to ENABLED for newly created User Pool Clients if no value is provided.
but we should be able to control it anyways.
prevent_user_existence_errors = "enabled" | "legacy"
+1
@realanmup @hildoer Please see #11604
+1
Support for this functionality has been merged and will release with version 2.54.0 of the Terraform AWS Provider, later this week. Thanks to @claydanford for the implementation. 👍
This has been released in version 2.54.0 of the Terraform AWS provider. Please see the Terraform documentation on provider versioning or reach out if you need any assistance upgrading.
For further feature requests or bug reports with this functionality, please create a new GitHub issue following the template for triage. Thanks!
I'm going to lock this issue because it has been closed for _30 days_ ⏳. This helps our maintainers find and focus on the active issues.
If you feel this issue should be reopened, we encourage creating a new issue linking back to this one for added context. Thanks!
Most helpful comment
@realanmup @hildoer Please see #11604