1 Answers
0
Accepted Answer
Hi,
You are right, this behavior is to protect Cognito customers from username enumeration risks. The behavior is highlighted in the managing error messages page and applied when prevent user existence error is enabled.
When you enable custom error responses, Amazon Cognito authentication APIs return a generic authentication failure response. The error response tells you the user name or password is incorrect. Amazon Cognito account confirmation and password recovery APIs return a response indicating a code was sent to a simulated delivery medium.
Relevant questions
Cognito Hosted UI customization not updating
asked 7 months agoCognito Forgot password email not received.
asked 2 years agocan we change the colour of "Forgot your password?" in the cognito UI login page ?
asked 4 months agoCognito Hosted UI to Custom UI
Accepted Answerasked 2 years agoCognito Hosted UI user email verification (using valid verification code) failed (according to UI) but user is confirmed.
asked 7 months agoAmazon Cognito hosted UI password reset code message
Accepted Answerasked 8 months agoIs there any way to display a "Confirm Password" field in the Cognito hosted UI?
asked 7 months agoDisable hosted UI
asked 4 years agoHow to translate Cognito Hosted UI Forms?
asked 5 months agoCognito Hosted UI TOTP or Amplify
asked 7 months ago