INNER CODE UNIT · TypeScript

preferredCount

aws-devtools-labs/aws-blocks · packages/bb-auth-cognito/src/index.ts:1514

		const preferredCount = deltas.filter(([, s]) => s === 'PREFERRED').length;
		if (preferredCount > 1) {
			throw new ApiError(
				'At most one factor may be set to PREFERRED per call',
				400,
				{ name: AuthCognitoErrors.InvalidParameter },
			);
		}

		// Cognito rejects enabling TOTP before it's been associated +
		// verified (`associateSoftwareToken` → `verifySoftwareToken`).
		// Mirror that rule: refuse to enable TOTP on a user whose
		// `totpVerified` flag is false.
		const enabling = deltas.filter(([, s]) => s === 'ENABLED' || s === 'PREFERRED' || s === 'NOT_PREFERRED');
		if (enabling.some(([f]) => f === 'TOTP') && !user.totpVerified) {
			throw new ApiError(
				'TOTP is not associated for this user. Call setUpTOTP + verifyTOTPSetup before enabling it as an MFA factor.',
				400,

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…