【文章标题】:I Used AWS Cognito for a Startup. I Wouldn’t Do It Again
【文章标题】:我在创业公司使用AWS Cognito的经历,再也不会重蹈覆辙

【文章正文】:
I Used AWS Cognito for a Startup. I Wouldn’t Do It Again.
我在创业公司使用了AWS Cognito,但绝不会再用第二次。

I let AWS Cognito gaslight me for three weeks so you don’t have to. Here’s the unfiltered autopsy.
我花了三周时间被AWS Cognito折磨得怀疑人生,只为让你避开这个坑。以下是毫无保留的深度剖析。

I was three days into setting up authentication for our startup when I realized something was wrong. Not “I missed a semicolon” wrong. More like “I followed every step in the documentation and the password reset flow still redirects to the wrong place” wrong.
在为公司配置认证系统的第三天,我就发现不对劲。不是”漏了个分号”这种小问题,而是”严格按文档操作后,密码重置流程仍会跳转到错误页面”的严重错误。

I had the docs open in twelve tabs. I had copy-pasted the code samples. I had even watched a tutorial from someone who sounded like they’d been through this exact nightmare before.
我打开了十二个文档标签页,复制粘贴了所有示例代码,甚至观看了某位过来人的教程——他讲述的语气仿佛刚从同样的噩梦中逃脱。

Here’s the thing. I’ve implemented authentication before. I’ve wrestled with Auth0, tamed Firebase Auth, and even rawdogged a custom JWT system that I’m not proud of but it worked. So when our startup needed auth and the team leaned toward Cognito because “it’s already in the AWS ecosystem and the first 50,000 monthly active users are free,” I thought, how bad could it be?
关键在于,我并非认证系统的新手。曾与Auth0搏斗过,驯服过Firebase Auth,甚至粗暴实现过一套虽不光彩但能用的自定义JWT系统。所以当团队因”它属于AWS生态且前5万月活用户免费”而倾向Cognito时,我想:能有多糟呢?

I regret everything.
现在我只想说:追悔莫及。

The Documentation Was Written for Five Different People at Once
文档试图同时满足五类人的需求

Reading Cognito docs feels like someone took three separate manuals, threw them in a blender, and then sprinkled in some outdated Stack Overflow answers for flavor.
阅读Cognito文档就像有人把三本手册扔进搅拌机,又撒了些过时的Stack Overflow答案调味。

AWS is trying to serve too many audiences simultaneously. You’ve got the enterprise architect who wants to understand the underlying identity protocols. You’ve got the frontend developer who just wants a login form. You’ve got the mobile developer who needs native SDKs. And the docs try to be everything to everyone, which means they end up being useful to exactly nobody.
AWS试图同时服务太多受众:想了解底层协议的企业架构师、只需要登录表单的前端开发者、需要原生SDK的移动开发者。文档想面面俱到,结果对谁都无用。

I’d search for “Cognito custom attribute validation” and land on a page that starts with a paragraph about directory schemas that assumes I’ve already read four other pages I didn’t know existed. There’s no clear linear path. It’s just a web of hyperlinks and prayers.
搜索”Cognito自定义属性验证”会跳转到以目录架构开头的页面,仿佛我已读过四个根本不存在的相关页面。没有清晰路径,只有超链接迷宫和祈祷。

And the code examples. Oh, the code examples. Half of them are for the old JavaScript SDK. Some reference the Amplify v1 API. Others use the raw AWS SDK. The docs don’t always clearly tell you which version they’re talking about, so you’re left playing detective with import statements.
至于代码示例——天啊那些示例!一半用旧版JavaScript SDK,有些引用Amplify v1 API,还有些用原生AWS SDK。文档从不说明版本,你只能像侦探般解析import语句。

The Day Amplify v6 Betrayed Me
Amplify v6背叛我的那一天

Speaking of versions. Let me tell you about the JavaScript library situation, because this one genuinely caught me off guard.
说到版本,必须提JavaScript库的变故——这记闷棍打得我措手不及。

When we started building, Amplify was on version 5. I wrote our auth flow, tested it, committed it, moved on to other features. A few weeks later, I came back to fix a bug and noticed some deprecation warnings in the console. No problem, I thought. I’ll just update to the latest version.
开发初期我们使用Amplify v5。我写完认证流程测试通过后就去开发其他功能。几周后回来修bug时发现控制台有废弃警告,心想:更新到最新版就好。

Friends. Amplify v6 didn’t just change a few method signatures. It fundamentally rearchitected how you interact with Cognito. Functions I had built entire UI flows around were gone. Replaced. Vanished. The migration guide existed, technically, but it felt more like a treasure map with half the landmarks missing.
朋友们,Amplify v6不止改了方法签名,而是彻底重构了与Cognito的交互方式。那些支撑整个UI流程的函数消失了。迁移指南像缺了关键标记的藏宝图。

I rewrote the code. Not refactored. Rewrote. Authentication logic that was working perfectly fine in production had to be rebuilt because the library maintainers decided the old API was no longer the blessed path. That’s not an upgrade. That’s a hostage situation.
我重写了代码——不是重构,是重写。仅因维护者宣布旧API非正统,生产环境运行良好的认证逻辑就得推倒重来。这不是升级,是绑架。

Local Development is a Special Kind of Pain
本地开发是种特殊的折磨

Here’s a fun fact about Cognito: it’s cloud-based. I know, shocking. But what that means practically is that you can’t just spin up a local instance and test your auth flows offline. You’re always hitting actual AWS endpoints.
关于Cognito的冷知识:它是云服务(我知道这很震惊)。实际意味着你无法在本地离线测试认证流程,永远要连接真实AWS端点。

Now, there are tools like the serverless-offline plugin and local Cognito emulators that try to bridge this gap. But they’re community projects with varying levels of maintenance and fidelity. The official story from AWS is basically “test against the cloud,” which is great advice unless you’re on a plane, or your internet is spotty, or you just want fast iteration cycles without waiting for network round trips.
虽然有serverless-offline插件和本地模拟器试图弥补,但它们都是维护参差不齐的社区项目。AWS官方建议”直接在云端测试”——除非你在飞机上、网络不稳、或想快速迭代而不用等待网络往返。

I spent an embarrassing amount of time setting up a local mock that didn’t quite match the real thing, which meant bugs would slip through locally and show up in staging. The whole point of local development is catching issues early, and Cognito actively works against that.
我耗费大量时间搭建的本地模拟器与真实环境存在差异,导致本地测试通过的bug在预发环境暴露。本地开发本应早发现问题,Cognito却反其道而行。

You Want Customization? Best I Can Do is a Logo
想要定制化?最多换个Logo

This one stung.
这点最扎心。

The hosted UI that Cognito provides is functional. It’s there. It works, mostly. But if you want it to look like your brand and not like an AWS service wearing a costume, you’re going to have a bad time.
Cognito提供的托管UI能用,勉强算工作正常。但若想让它符合品牌调性而非像套了层皮的AWS服务,你会很痛苦。

You can change the logo. You can tweak some CSS via the console. But the layout, the structure, the overall feel? That’s AWS’s house, and you’re just renting a room. If you need anything beyond basic customization, the advice from the community is usually “build your own UI using the SDK.” Which, fine, I get it. But at that point, what exactly is the hosted UI saving me?
你能换Logo,通过控制台微调CSS。但布局、结构、整体风格?那是AWS的地盘,你只是租客。需要深度定制时,社区建议通常是”用SDK自建UI”。好吧我懂,但既然如此,托管UI到底省了什么?

The Email-Only Configuration That Broke My Spirit
仅支持邮件的配置让我崩溃

Let me tell you about the moment I almost threw my laptop out a window.
说说我差点把笔记本扔出窗外的时刻。

Our app only needed em…
我们的应用只需要邮…