aws-samples / iam-identity-center-team

Open-source temporary elevated access solution for AWS IAM Identity Center.
https://aws-samples.github.io/iam-identity-center-team/
MIT No Attribution
249 stars 59 forks source link

Upgrading botches login completely - TEAM is unusable #228

Closed PeterBengtson closed 2 months ago

PeterBengtson commented 2 months ago

Describe the bug We have an installation of TEAM which has worked flawlessly for over a year. Today, upgrading to the latest version according to the instructions in the repo makes it impossible to login. Instead I get an error box saying "Login option is not available. Please try another one". Trying to log in from the Amplify console has an entirely different behaviour. (see screenshots below)

As I said, nothing has been changed or modified since installation. All we have done is update TEAM. Logging out and in again doesn't fix the problem. We are now completely shut out of JIT access possibilities.

Grateful for any input or ideas.

To Reproduce Just install the latest version.

Expected behavior When I click the TEAM application in the AWS access portal, I expect to be logged in to the TEAM application, just as before.

Screenshots This is how the normal login TEAM application presents itself:

Screenshot 2024-04-21 at 15 34 55

However, clicking on it produces this:

Screenshot 2024-04-21 at 15 34 59

.. but gives an error like so:

Screenshot 2024-04-21 at 15 35 00

Trying to log in from the Amplify console, here:

Screenshot 2024-04-21 at 15 35 15

... instead takes us to the TEAM login screen with no further autodirect:

Screenshot 2024-04-21 at 15 35 19

... and clicking federated sign-in produces this:

Screenshot 2024-04-21 at 15 35 23

... which indicates to me that something is amiss with Cognito.

The application hasn't been modified in any way. The parameter file contains entries for everything except the custom domain (we don't use one):

Screenshot 2024-04-21 at 15 41 58