Implementation for accessing CognitoIdentity Amazon Cognito

Amazon Cognito is a web service that delivers scoped temporary credentials to mobile devices and other untrusted environments. Amazon Cognito uniquely identifies a device and supplies the user with a consistent identity over the lifetime of an application.

Using Amazon Cognito, you can enable authentication with one or more third-party identity providers (Facebook, Google, or Login with Amazon), and you can also choose to support unauthenticated access from your app. Cognito delivers a unique identifier for each user and acts as an OpenID token provider trusted by AWS Security Token Service (STS) to access temporary, limited-privilege AWS credentials.

To provide end-user credentials, first make an unsigned call to GetId. If the end user is authenticated with one of the supported identity providers, set the Logins map with the identity provider token. GetId returns a unique identifier for the user.

Next, make an unsigned call to GetCredentialsForIdentity. This call expects the same Logins map as the GetId call, as well as the IdentityID originally returned by GetId. Assuming your identity pool has been configured via the SetIdentityPoolRoles operation, GetCredentialsForIdentity will return AWS credentials for your use. If your pool has not been configured with SetIdentityPoolRoles, or if you want to follow legacy flow, make an unsigned call to GetOpenIdToken, which returns the OpenID token necessary to call STS and retrieve AWS credentials. This call expects the same Logins map as the GetId call, as well as the IdentityID originally returned by GetId. The token returned by GetOpenIdToken can be passed to the STS operation AssumeRoleWithWebIdentity to retrieve AWS credentials.

If you want to use Amazon Cognito in an Android, iOS, or Unity application, you will probably want to make API calls via the AWS Mobile SDK. To learn more, see the AWS Mobile SDK Developer Guide.

Inheritance: AmazonServiceClient, IAmazonCognitoIdentity
        public CognitoAWSCredentials(string accountId, string identityPoolId, string unAuthRoleArn, string authRoleArn, IAmazonCognitoIdentity cibClient, IAmazonSecurityTokenService stsClient)
        {
            if (string.IsNullOrEmpty(identityPoolId))
            {
                throw new ArgumentNullException("identityPoolId");
            }
            if (cibClient == null)
            {
                throw new ArgumentNullException("cibClient");
            }
            if ((unAuthRoleArn != null || authRoleArn != null) && stsClient == null)
            {
                throw new ArgumentNullException("stsClient");
            }
            AccountId      = accountId;
            IdentityPoolId = identityPoolId;
            UnAuthRoleArn  = unAuthRoleArn;
            AuthRoleArn    = authRoleArn;
            Logins         = new Dictionary <string, string>(StringComparer.Ordinal);
            cib            = (AmazonCognitoIdentityClient)cibClient;
            sts            = (AmazonSecurityTokenServiceClient)stsClient;
            string cachedIdentityId = GetCachedIdentityId();

            if (!string.IsNullOrEmpty(cachedIdentityId))
            {
                UpdateIdentity(cachedIdentityId);
                currentState = GetCachedCredentials();
            }
        }
        private CognitoCredential LetUsDealWithTheAWSCognitoIDStuff(String userID)
        {
            String AccessKey = ConfigurationManager.AppSettings["AWSAccessKeyId"];
               String SecretAccessKey = ConfigurationManager.AppSettings["AWSSecretAccessKey"];
               BasicAWSCredentials basicAWSCredentials = new BasicAWSCredentials(AccessKey, SecretAccessKey);

               AmazonCognitoIdentityConfig config = new AmazonCognitoIdentityConfig();
               config.ServiceURL = "ec2.us-east-1.amazonaws.com";
               config.RegionEndpoint = Amazon.RegionEndpoint.USEast1;

               AmazonCognitoIdentityClient identityClient = new AmazonCognitoIdentityClient(basicAWSCredentials, config);

               GetOpenIdTokenForDeveloperIdentityRequest idRequest = new GetOpenIdTokenForDeveloperIdentityRequest();
               idRequest.IdentityPoolId = "us-east-1:c812ebc0-88e3-44d9-84e4-8e2ac888d19f";

               Dictionary<string, string> userLogins =  new Dictionary<string, string>();
               userLogins.Add("Login.WhatsNowWebService", userID);
               idRequest.Logins = userLogins;

               idRequest.TokenDuration = 60 * 5;
               GetOpenIdTokenForDeveloperIdentityResponse idResp = identityClient.GetOpenIdTokenForDeveloperIdentity(idRequest);

               string cognitoId = idResp.IdentityId;
               string oidToken = idResp.Token;

               CognitoCredential cc = new CognitoCredential();
               cc.CognitoID = cognitoId;
               cc.CognitoToken = oidToken;

               return cc;
        }