cognito library

AWS Cognito.

Classes

AppConstant<T>
A value the Stack hands to application code as a static const in the generated AppExports file — known when synth runs, so the app compiles against it.
AppExports
Where synth writes the Dart file application code imports: the Stack's constants, as the static const members of <name>Constants, and a typed reader of its Terraform outputs, <name>Outputs.
AttributeRef<T>
Public for sealed pattern matching, but constructor is private — only TfRef.attribute() may construct instances.
AwsCognitoIdentityPool
Factory wrapper for aws_cognito_identity_pool.
AwsCognitoIdentityPoolProviderPrincipalTag
Factory wrapper for aws_cognito_identity_pool_provider_principal_tag.
AwsCognitoIdentityPoolRolesAttachment
Factory wrapper for aws_cognito_identity_pool_roles_attachment.
AwsCognitoIdentityProvider
Factory wrapper for aws_cognito_identity_provider.
AwsCognitoLogDeliveryConfiguration
Factory wrapper for aws_cognito_log_delivery_configuration.
AwsCognitoManagedLoginBranding
Factory wrapper for aws_cognito_managed_login_branding.
AwsCognitoManagedUserPoolClient
Factory wrapper for aws_cognito_managed_user_pool_client.
AwsCognitoResourceServer
Factory wrapper for aws_cognito_resource_server.
AwsCognitoRiskConfiguration
Factory wrapper for aws_cognito_risk_configuration.
AwsCognitoUser
Factory wrapper for aws_cognito_user.
AwsCognitoUserGroup
Factory wrapper for aws_cognito_user_group.
AwsCognitoUserInGroup
Factory wrapper for aws_cognito_user_in_group.
AwsCognitoUserPool
Factory wrapper for aws_cognito_user_pool.
AwsCognitoUserPoolClient
Factory wrapper for aws_cognito_user_pool_client.
AwsCognitoUserPoolDomain
Factory wrapper for aws_cognito_user_pool_domain.
AwsCognitoUserPoolUiCustomization
Factory wrapper for aws_cognito_user_pool_ui_customization.
CognitoIdentityPoolCognitoIdentityProviders
Typed helper for the cognito_identity_providers block of aws_cognito_identity_pool (derived from provider schema).
CognitoIdentityPoolRolesAttachmentMappingRule
Typed helper for the role_mapping.mapping_rule block of aws_cognito_identity_pool_roles_attachment (derived from provider schema).
CognitoIdentityPoolRolesAttachmentRoleMapping
Typed helper for the role_mapping block of aws_cognito_identity_pool_roles_attachment (derived from provider schema).
CognitoLogDeliveryConfigurationCloudWatchLogsConfiguration
Typed helper for the log_configurations.cloud_watch_logs_configuration block of aws_cognito_log_delivery_configuration (derived from provider schema).
CognitoLogDeliveryConfigurationFirehoseConfiguration
Typed helper for the log_configurations.firehose_configuration block of aws_cognito_log_delivery_configuration (derived from provider schema).
CognitoLogDeliveryConfigurationLogConfigurations
Typed helper for the log_configurations block of aws_cognito_log_delivery_configuration (derived from provider schema).
CognitoLogDeliveryConfigurationS3Configuration
Typed helper for the log_configurations.s3_configuration block of aws_cognito_log_delivery_configuration (derived from provider schema).
CognitoManagedLoginBrandingAsset
Typed helper for the asset block of aws_cognito_managed_login_branding (derived from provider schema).
CognitoManagedLoginBrandingStyle
Exactly one of settings, use_cognito_provided_values on aws_cognito_managed_login_branding: the provider rejects none and more than one, so each variant sets one of them.
CognitoManagedLoginBrandingStyleSettings
The CognitoManagedLoginBrandingStyle.settings choice: sets settings.
CognitoManagedLoginBrandingStyleUseCognitoProvidedValues
The CognitoManagedLoginBrandingStyle.useCognitoProvidedValues choice: sets use_cognito_provided_values.
CognitoManagedUserPoolClientAnalyticsConfiguration
Typed helper for the analytics_configuration block of aws_cognito_managed_user_pool_client (derived from provider schema).
CognitoManagedUserPoolClientApplication
Exactly one of application_arn, application_id on the analytics_configuration block of aws_cognito_managed_user_pool_client: the provider rejects none and more than one, so each variant sets one of them.
CognitoManagedUserPoolClientApplicationArn
The CognitoManagedUserPoolClientApplication.applicationArn choice: sets application_arn.
CognitoManagedUserPoolClientApplicationId
The CognitoManagedUserPoolClientApplication.applicationId choice: sets application_id.
CognitoManagedUserPoolClientName
Exactly one of name_pattern, name_prefix on aws_cognito_managed_user_pool_client: the provider rejects none and more than one, so each variant sets one of them.
CognitoManagedUserPoolClientNamePattern
The CognitoManagedUserPoolClientName.namePattern choice: sets name_pattern.
CognitoManagedUserPoolClientNamePrefix
The CognitoManagedUserPoolClientName.namePrefix choice: sets name_prefix.
CognitoManagedUserPoolClientRefreshTokenRotation
Typed helper for the refresh_token_rotation block of aws_cognito_managed_user_pool_client (derived from provider schema).
CognitoManagedUserPoolClientTokenValidityUnits
Typed helper for the token_validity_units block of aws_cognito_managed_user_pool_client (derived from provider schema).
CognitoResourceServerScope
Typed helper for the scope block of aws_cognito_resource_server (derived from provider schema).
CognitoRiskConfigurationAccountTakeoverRiskConfiguration
Typed helper for the account_takeover_risk_configuration block of aws_cognito_risk_configuration (derived from provider schema).
CognitoRiskConfigurationAccountTakeoverRiskConfigurationActions
Typed helper for the account_takeover_risk_configuration.actions block of aws_cognito_risk_configuration (derived from provider schema).
CognitoRiskConfigurationBlockEmail
Typed helper for the account_takeover_risk_configuration.notify_configuration.block_email block of aws_cognito_risk_configuration (derived from provider schema).
CognitoRiskConfigurationCompromisedCredentialsRiskConfiguration
Typed helper for the compromised_credentials_risk_configuration block of aws_cognito_risk_configuration (derived from provider schema).
CognitoRiskConfigurationCompromisedCredentialsRiskConfigurationActions
Typed helper for the compromised_credentials_risk_configuration.actions block of aws_cognito_risk_configuration (derived from provider schema).
CognitoRiskConfigurationHighAction
Typed helper for the account_takeover_risk_configuration.actions.high_action block of aws_cognito_risk_configuration (derived from provider schema).
CognitoRiskConfigurationLowAction
Typed helper for the account_takeover_risk_configuration.actions.low_action block of aws_cognito_risk_configuration (derived from provider schema).
CognitoRiskConfigurationMediumAction
Typed helper for the account_takeover_risk_configuration.actions.medium_action block of aws_cognito_risk_configuration (derived from provider schema).
CognitoRiskConfigurationMfaEmail
Typed helper for the account_takeover_risk_configuration.notify_configuration.mfa_email block of aws_cognito_risk_configuration (derived from provider schema).
CognitoRiskConfigurationNoActionEmail
Typed helper for the account_takeover_risk_configuration.notify_configuration.no_action_email block of aws_cognito_risk_configuration (derived from provider schema).
CognitoRiskConfigurationNotifyConfiguration
Typed helper for the account_takeover_risk_configuration.notify_configuration block of aws_cognito_risk_configuration (derived from provider schema).
CognitoRiskConfigurationRiskExceptionConfiguration
Typed helper for the risk_exception_configuration block of aws_cognito_risk_configuration (derived from provider schema).
CognitoUserPassword
At most one of password, temporary_password on aws_cognito_user: the provider rejects more than one, so each variant sets one of them and a null choice sets none.
CognitoUserPasswordChoice
The CognitoUserPassword.password choice: sets password.
CognitoUserPoolAccountRecoverySetting
Typed helper for the account_recovery_setting block of aws_cognito_user_pool (derived from provider schema).
CognitoUserPoolAddOns
Typed helper for the user_pool_add_ons block of aws_cognito_user_pool (derived from provider schema).
CognitoUserPoolAdminCreateUserConfig
Typed helper for the admin_create_user_config block of aws_cognito_user_pool (derived from provider schema).
CognitoUserPoolAdvancedSecurityAdditionalFlows
Typed helper for the user_pool_add_ons.advanced_security_additional_flows block of aws_cognito_user_pool (derived from provider schema).
CognitoUserPoolClientAnalyticsConfiguration
Typed helper for the analytics_configuration block of aws_cognito_user_pool_client (derived from provider schema).
CognitoUserPoolClientApplication
Exactly one of application_arn, application_id on the analytics_configuration block of aws_cognito_user_pool_client: the provider rejects none and more than one, so each variant sets one of them.
CognitoUserPoolClientApplicationArn
The CognitoUserPoolClientApplication.applicationArn choice: sets application_arn.
CognitoUserPoolClientApplicationId
The CognitoUserPoolClientApplication.applicationId choice: sets application_id.
CognitoUserPoolClientRefreshTokenRotation
Typed helper for the refresh_token_rotation block of aws_cognito_user_pool_client (derived from provider schema).
CognitoUserPoolClientTokenValidityUnits
Typed helper for the token_validity_units block of aws_cognito_user_pool_client (derived from provider schema).
CognitoUserPoolCustomEmailSender
Typed helper for the lambda_config.custom_email_sender block of aws_cognito_user_pool (derived from provider schema).
CognitoUserPoolCustomSmsSender
Typed helper for the lambda_config.custom_sms_sender block of aws_cognito_user_pool (derived from provider schema).
CognitoUserPoolDeviceConfiguration
Typed helper for the device_configuration block of aws_cognito_user_pool (derived from provider schema).
CognitoUserPoolEmailConfiguration
Typed helper for the email_configuration block of aws_cognito_user_pool (derived from provider schema).
CognitoUserPoolEmailMfaConfiguration
Typed helper for the email_mfa_configuration block of aws_cognito_user_pool (derived from provider schema).
CognitoUserPoolInviteMessageTemplate
Typed helper for the admin_create_user_config.invite_message_template block of aws_cognito_user_pool (derived from provider schema).
CognitoUserPoolLambdaConfig
Typed helper for the lambda_config block of aws_cognito_user_pool (derived from provider schema).
CognitoUserPoolNumberAttributeConstraints
Typed helper for the schema.number_attribute_constraints block of aws_cognito_user_pool (derived from provider schema).
CognitoUserPoolPasswordPolicy
Typed helper for the password_policy block of aws_cognito_user_pool (derived from provider schema).
CognitoUserPoolPreTokenGenerationConfig
Typed helper for the lambda_config.pre_token_generation_config block of aws_cognito_user_pool (derived from provider schema).
CognitoUserPoolRecoveryMechanism
Typed helper for the account_recovery_setting.recovery_mechanism block of aws_cognito_user_pool (derived from provider schema).
CognitoUserPoolSchema
Typed helper for the schema block of aws_cognito_user_pool (derived from provider schema).
CognitoUserPoolSignInAttributes
At most one of alias_attributes, username_attributes on aws_cognito_user_pool: the provider rejects more than one, so each variant sets one of them and a null choice sets none.
CognitoUserPoolSignInAttributesAliasAttributes
The CognitoUserPoolSignInAttributes.aliasAttributes choice: sets alias_attributes.
CognitoUserPoolSignInAttributesUsernameAttributes
The CognitoUserPoolSignInAttributes.usernameAttributes choice: sets username_attributes.
CognitoUserPoolSignInPolicy
Typed helper for the sign_in_policy block of aws_cognito_user_pool (derived from provider schema).
CognitoUserPoolSmsConfiguration
Typed helper for the sms_configuration block of aws_cognito_user_pool (derived from provider schema).
CognitoUserPoolSoftwareTokenMfaConfiguration
Typed helper for the software_token_mfa_configuration block of aws_cognito_user_pool (derived from provider schema).
CognitoUserPoolStringAttributeConstraints
Typed helper for the schema.string_attribute_constraints block of aws_cognito_user_pool (derived from provider schema).
CognitoUserPoolUserAttributeUpdateSettings
Typed helper for the user_attribute_update_settings block of aws_cognito_user_pool (derived from provider schema).
CognitoUserPoolUsernameConfiguration
Typed helper for the username_configuration block of aws_cognito_user_pool (derived from provider schema).
CognitoUserPoolVerificationMessageTemplate
Typed helper for the verification_message_template block of aws_cognito_user_pool (derived from provider schema).
CognitoUserPoolWebAuthnConfiguration
Typed helper for the web_authn_configuration block of aws_cognito_user_pool (derived from provider schema).
CognitoUserTemporaryPassword
The CognitoUserPassword.temporaryPassword choice: sets temporary_password.
DartDefineOutput
An output whose value is the client build's --dart-define file, registered with Stack.addDartDefineOutput.
Data
Base of every user-instantiable Terraform data block.
DataAwsCognitoIdentityPool
Factory wrapper for aws_cognito_identity_pool.
DataAwsCognitoUserGroup
Factory wrapper for aws_cognito_user_group.
DataAwsCognitoUserGroups
Factory wrapper for aws_cognito_user_groups.
DataAwsCognitoUserPool
Factory wrapper for aws_cognito_user_pool.
DataAwsCognitoUserPoolClient
Factory wrapper for aws_cognito_user_pool_client.
DataAwsCognitoUserPoolClients
Factory wrapper for aws_cognito_user_pool_clients.
DataAwsCognitoUserPools
Factory wrapper for aws_cognito_user_pools.
DataAwsCognitoUserPoolSigningCertificate
Factory wrapper for aws_cognito_user_pool_signing_certificate.
DataRef<T>
Public for sealed pattern matching, but constructor is private — only TfRef.data() may construct instances.
EnvironmentConstant
The AppConstant.fromEnvironment choice.
GcsBackend
terraform { backend "gcs" { ... } } configuration.
IgnoreAllChanges
IgnoreChanges.all.
IgnoreAttributes
IgnoreChanges.of.
IgnoreChanges
What ignore_changes covers: every attribute, or the listed ones.
InvalidDartDefineOutput
An output of Stack.addDartDefineOutput that cannot carry what it names: an output that is not registered, is sensitive or has no environment value, two outputs read from one variable, or no output at all.
InvalidLifecycle
A lifecycle block Terraform rejects: a data source (or one of its attributes) in replaceTriggeredBy, all inside IgnoreChanges.of, or a condition with an empty error message.
InvalidMoveTarget
A moved block whose to names no resource of the Stack.
InvalidTimeout
A negative timeouts duration.
LifecycleCondition
A precondition or postcondition block: Terraform fails the plan (LifecycleCondition.pre) or the apply (LifecycleCondition.post) with errorMessage when condition is false.
LifecycleOptions
lifecycle { ... } block on a resource.
LocalBackend
terraform { backend "local" { ... } } configuration.
MissingProvider
A block needs a provider configuration the Stack does not register: the provider its type implies (google for google_pubsub_topic), the one its provider meta-argument names, or one a module call passes on.
ModuleCall
A module "<localName>" { ... } call as a Dart value.
NoProviders
The Stack registers no provider, but declares resources or data sources.
ProviderConflict
Two provider registrations Terraform rejects together: two defaults of one name, a repeated alias, an alias that is not an identifier, or configurations of one name with different source / version constraints.
RefConstant<T>
The AppConstant.ref choice.
ReplaceTrigger
What lifecycle.replaceTriggeredBy lists: a resource of the Stack or an attribute getter of one. Resource and TfRef implement it; synth reports a data source or a data-source attribute as an InvalidLifecycle.
Resource
Base of every user-instantiable Terraform resource.
ResourceRef
Public for sealed pattern matching, but constructor is private — only TfRef.resource() may construct instances.
S3Backend
terraform { backend "s3" { ... } } configuration.
Sensitive<T>
What an argument Terraform marks sensitive takes: a variable, an expression or an attribute getter — a value Terraform resolves, never a Dart literal that would be written into main.tf.json.
SensitiveLiteral
A sensitive field is set to a literal, which would write the secret in plain text into main.tf.json.
Stack
User-extended IaC composition root.
StackBackend
Lightweight backend hook. Core ships GcsBackend, S3Backend, and LocalBackend; anything else implements this interface in the caller. The Stack only stores the value and exposes a discriminator for synth's terraform { backend ... } emitter.
StackProvider
Coordination interface between Stack (in this package) and concrete providers (e.g. GoogleProvider in terradart_google). Concrete providers implement every getter using their baked-in constants from Stage 2 codegen.
SynthIssue
One reason a Stack cannot be synthesized.
SynthResult
Bundle returned by StackSynth.synth.
TfAddressed
Anything that exposes a Terraform address, e.g. google_pubsub_topic.orders.
TfArg<T>
A Terraform argument: a Dart-side literal, a reference to another block's attribute (TfRef), a variable or a raw expression.
TfArgExpression<T>
A raw Terraform expression — the tf.json template string, verbatim.
TfArgLiteral<T>
TfArgVariable<T>
TfCollectionType
list(...), set(...) or map(...).
TfMoved
One moved { from = ... to = ... } block: the state object at from now belongs to the resource at to, so a rename does not become a destroy-and-create.
TfObjectType
object({ ... }).
TfOptionalType
optional(<type>[, <default>]).
TfOutput<T>
An output "<name>" { value = ... } block, registered with Stack.addOutput.
TfPrimitiveType
string, number, bool or any.
TfRef<T>
A Terraform-side reference: an attribute of a resource (AttributeRef) or a data source (DataRef), or a whole resource (ResourceRef).
TfTimeouts
timeouts { ... } on a resource or data source: how long Terraform waits for each operation before giving up.
TfTupleType
tuple([...]).
TfType
A Terraform type constraint: string, list(number), object({ name = string }).
TfVariable
One variable "<name>" { ... } declaration.
UndeclaredVariable
A TfArg.variable or var.<name> in an expression names a variable the Stack does not declare.
UnregisteredReference
A block references another block that was never registered on the Stack: built, but not passed to add(...) / addModule(...).
UnresolvableConstant
An AppConstant.ref whose value is not known at synth: the attribute is not set to a literal, is sensitive, does not match the constant's type, or belongs to a block that is not registered.
ValueConstant<T>
The AppConstant.value choice.

Enums

ResourceKind
Whether a Stack entry is a resource block or a data block in Terraform JSON.

Extension Types

CognitoIdentityPoolRolesAttachmentAmbiguousRoleResolution
ambiguous_role_resolution — derived from the provider schema description.
CognitoIdentityPoolRolesAttachmentMatchType
match_type — derived from the provider schema description.
CognitoIdentityPoolRolesAttachmentType
type — derived from the provider schema description.
CognitoIdentityProviderType
Cognito Identity Provider enum for provider_type.
CognitoLogDeliveryConfigurationEventSource
event_source — derived from the provider schema description.
CognitoLogDeliveryConfigurationLogLevel
log_level — derived from the provider schema description.
CognitoManagedLoginBrandingCategory
category — derived from the provider schema description.
CognitoManagedLoginBrandingColorMode
color_mode — derived from the provider schema description.
CognitoManagedLoginBrandingExtension
extension — derived from the provider schema description.
CognitoManagedUserPoolClientAllowedOauthFlows
Cognito Managed User Pool Client Allowed Oauth enum for allowed_oauth_flows.
CognitoManagedUserPoolClientExplicitAuthFlows
Cognito Managed User Pool Client Explicit Auth enum for explicit_auth_flows.
CognitoManagedUserPoolClientFeature
feature — derived from the provider schema description.
CognitoManagedUserPoolClientPreventUserExistenceErrors
Cognito Managed User Pool Client Prevent User Existence enum for prevent_user_existence_errors.
CognitoRiskConfigurationEventAction
event_action — derived from the provider schema description.
CognitoRiskConfigurationEventFilter
event_filter — derived from the provider schema description.
CognitoRiskConfigurationHighActionEventAction
event_action — derived from the provider schema description.
CognitoUserDesiredDeliveryMediums
Cognito User Desired Delivery enum for desired_delivery_mediums.
CognitoUserMessageAction
Cognito User Message enum for message_action.
CognitoUserPoolAdvancedSecurityMode
advanced_security_mode — derived from the provider schema description.
CognitoUserPoolAliasAttributes
Cognito User Pool Alias enum for alias_attributes.
CognitoUserPoolAllowedFirstAuthFactors
allowed_first_auth_factors — derived from the provider schema description.
CognitoUserPoolAttributeDataType
attribute_data_type — derived from the provider schema description.
CognitoUserPoolAttributesRequireVerificationBeforeUpdate
attributes_require_verification_before_update — derived from the provider schema description.
CognitoUserPoolAutoVerifiedAttributes
Cognito User Pool Auto Verified enum for auto_verified_attributes.
CognitoUserPoolClientAllowedOauthFlows
Cognito User Pool Client Allowed Oauth enum for allowed_oauth_flows.
CognitoUserPoolClientExplicitAuthFlows
Cognito User Pool Client Explicit Auth enum for explicit_auth_flows.
CognitoUserPoolClientFeature
feature — derived from the provider schema description.
CognitoUserPoolClientPreventUserExistenceErrors
Cognito User Pool Client Prevent User Existence enum for prevent_user_existence_errors.
CognitoUserPoolCustomAuthMode
custom_auth_mode — derived from the provider schema description.
CognitoUserPoolCustomEmailSenderLambdaVersion
lambda_version — derived from the provider schema description.
CognitoUserPoolDefaultEmailOption
default_email_option — derived from the provider schema description.
CognitoUserPoolDeletionProtection
Cognito User Pool Deletion enum for deletion_protection.
CognitoUserPoolEmailSendingAccount
email_sending_account — derived from the provider schema description.
CognitoUserPoolMfaConfiguration
Cognito User Pool Mfa enum for mfa_configuration.
CognitoUserPoolPreTokenGenerationConfigLambdaVersion
lambda_version — derived from the provider schema description.
CognitoUserPoolRecoveryMechanismName
name — derived from the provider schema description.
CognitoUserPoolTier
Cognito User Pool enum for user_pool_tier.
CognitoUserPoolUsernameAttributes
Cognito User Pool Username enum for username_attributes.
CognitoUserPoolUserVerification
user_verification — derived from the provider schema description.
OutputEnvironment
The environment Stack.outputEnvironment returns: each variable and its value, in registration order.
RefTo
A reference to a resource of type R, for an argument that names another resource (network, vpc_id, role_arn, ...).

Extensions

RefToList on TfArg<List<RefTo<R>>>
A list-valued reference argument (security_group_ids, subnet_ids): a literal list of RefTos, or one value that is the whole list (TfArg.variable('subnet_ids'), TfArg.expression(...)).
TerraformDurationExt on Duration
Converts a Dart Duration into a Terraform duration string ("604800s").

Constants

terradartManifestVariable → const String
The environment variable the terradart command sets to the file runStack and runEnvironments describe what they wrote in.

Functions

runEnvironments<E extends Enum>(List<String> args, List<E> environments, Stack build(E env), {String dir(E env)?, String? workspace(E env)?, List<String> backendConfig(E env)?, E? defaultEnv}) → Future<void>
The entry point of a project with one Stack per environment. The environments are the members of an enum of the project's own — any names, each carrying its values — so the Stack takes a typed env and derives everything per environment from it, its backend included:
runStack(List<String> args, Stack build(), {String out = 'tf-out'}) → Future<void>
The entry point of a project with one Stack: writes it to out.

Exceptions / Errors

DuplicateModuleError
A ModuleCall registered twice under one name.
DuplicateResourceError
Thrown by Stack.add when an entry with the same (kind, terraformType, localName) triple is registered twice.
SynthException
Thrown by Stack.synth() and Stack.writeTo() when the Stack has one or more SynthIssues. Nothing is written.