user_pool_risk_configuration_attachments
Creates, updates, deletes or gets an user_pool_risk_configuration_attachment resource or lists user_pool_risk_configuration_attachments in a region
Overview
| Name | user_pool_risk_configuration_attachments |
| Type | Resource |
| Description | Resource Type definition for AWS::Cognito::UserPoolRiskConfigurationAttachment |
| Id | awscc.cognito.user_pool_risk_configuration_attachments |
Fields
| Name | Datatype | Description |
|---|---|---|
user_pool_id | string | |
client_id | string | |
risk_exception_configuration | object | |
compromised_credentials_risk_configuration | object | |
account_takeover_risk_configuration | object | |
region | string | AWS region. |
For more information, see AWS::Cognito::UserPoolRiskConfigurationAttachment.
Methods
| Name | Accessible by | Required Params |
|---|---|---|
create_resource | INSERT | UserPoolId, ClientId, region |
delete_resource | DELETE | Identifier, region |
update_resource | UPDATE | Identifier, PatchDocument, region |
get_resource | SELECT | Identifier, region |
SELECT examples
Gets all properties from an individual user_pool_risk_configuration_attachment.
SELECT
region,
user_pool_id,
client_id,
risk_exception_configuration,
compromised_credentials_risk_configuration,
account_takeover_risk_configuration
FROM awscc.cognito.user_pool_risk_configuration_attachments
WHERE
region = 'us-east-1' AND
Identifier = '{{ user_pool_id }}|{{ client_id }}';
INSERT example
Use the following StackQL query and manifest file to create a new user_pool_risk_configuration_attachment resource, using stack-deploy.
- Required Properties
- All Properties
- Manifest
/*+ create */
INSERT INTO awscc.cognito.user_pool_risk_configuration_attachments (
UserPoolId,
ClientId,
region
)
SELECT
'{{ user_pool_id }}',
'{{ client_id }}',
'{{ region }}';
/*+ create */
INSERT INTO awscc.cognito.user_pool_risk_configuration_attachments (
UserPoolId,
ClientId,
RiskExceptionConfiguration,
CompromisedCredentialsRiskConfiguration,
AccountTakeoverRiskConfiguration,
region
)
SELECT
'{{ user_pool_id }}',
'{{ client_id }}',
'{{ risk_exception_configuration }}',
'{{ compromised_credentials_risk_configuration }}',
'{{ account_takeover_risk_configuration }}',
'{{ region }}';
version: 1
name: stack name
description: stack description
providers:
- aws
globals:
- name: region
value: '{{ vars.AWS_REGION }}'
resources:
- name: user_pool_risk_configuration_attachment
props:
- name: user_pool_id
value: '{{ user_pool_id }}'
- name: client_id
value: '{{ client_id }}'
- name: risk_exception_configuration
value:
blocked_ip_range_list:
- '{{ blocked_ip_range_list[0] }}'
skipped_ip_range_list:
- '{{ skipped_ip_range_list[0] }}'
- name: compromised_credentials_risk_configuration
value:
actions:
event_action: '{{ event_action }}'
event_filter:
- '{{ event_filter[0] }}'
- name: account_takeover_risk_configuration
value:
actions:
high_action:
event_action: '{{ event_action }}'
notify: '{{ notify }}'
low_action: null
medium_action: null
notify_configuration:
block_email:
html_body: '{{ html_body }}'
subject: '{{ subject }}'
text_body: '{{ text_body }}'
mfa_email: null
no_action_email: null
from: '{{ from }}'
reply_to: '{{ reply_to }}'
source_arn: '{{ source_arn }}'
UPDATE example
Use the following StackQL query and manifest file to update a user_pool_risk_configuration_attachment resource, using stack-deploy.
/*+ update */
UPDATE awscc.cognito.user_pool_risk_configuration_attachments
SET PatchDocument = string('{{ {
"RiskExceptionConfiguration": risk_exception_configuration,
"CompromisedCredentialsRiskConfiguration": compromised_credentials_risk_configuration,
"AccountTakeoverRiskConfiguration": account_takeover_risk_configuration
} | generate_patch_document }}')
WHERE
region = '{{ region }}' AND
Identifier = '{{ user_pool_id }}|{{ client_id }}';
DELETE example
/*+ delete */
DELETE FROM awscc.cognito.user_pool_risk_configuration_attachments
WHERE
Identifier = '{{ user_pool_id }}|{{ client_id }}' AND
region = 'us-east-1';
Permissions
To operate on the user_pool_risk_configuration_attachments resource, the following permissions are required:
- Create
- Read
- Update
- Delete
cognito-idp:SetRiskConfiguration,
cognito-idp:DescribeRiskConfiguration,
iam:PassRole
cognito-idp:DescribeRiskConfiguration
cognito-idp:SetRiskConfiguration,
cognito-idp:DescribeRiskConfiguration,
iam:PassRole
cognito-idp:SetRiskConfiguration,
cognito-idp:DescribeRiskConfiguration