AWS Lambda function for authorizing requests to an API Gateway via a Cognito User Pool.
352
This is a AWS Lambda function for authorizing requests to an API Gateway through a Cognito Userpool. This function will decode a Cognito JWT token in a request's Authorization header and then return a policy statement to inform API Gateway whether or not the incoming request is authorized to access the resource.
See documentation for more information on using a Lambda authorizer in an API Gateway.
The source code for this Lambda can be found here.
The following variables need delivered to the Lambda execution environment.
ACCOUNT_ID: Identification number for AWS account.
API_ID: Physical identification number for API Gateway REST API deployment.
USERPOOL_ID: Cognito Userpool identification number.
CLIENT_ID: Physicacl identification number for the Cognito Client.
REGION: Region where the API gateway is hosted.
GROUP: Optional. If GROUP is specified, the user associated with incoming request must belong to the specified group name, found in the cognito:groups property in the JWT payload. If the user does not belong to this group, request will be rejected. If GROUP is not specified, function will only validate the authenticity of the JWT.
There are several resources needed to hook this function into an existing API Gateway. The API Gateway authorizer will need an execution role attached to it, with permission invoke the Lambda function, so this role will need created, if it does not already exist.
The following CloudFormation template will provision the IAM role for the gateway authorizer to attach, the API Gateway authorizer and the Lambda function that gets invoked as the authorizer.
NOTE : <> indicate this value needs replaced.
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
applicationName:
Type: String
Description: Application namespace where resources are being deployed
Default: demo
Resources:
APIExecutorRole:
Type: AWS::IAM::Role
Properties:
Description: !Sub Assumed role for API Gateway to accecss ${applicationName} resources.
Path: !Sub "/${applicationName}/"
AssumeRolePolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Principal:
Service:
- apigateway.amazonaws.com
Action:
- "sts:AssumeRole"
Policies:
- PolicyName: !Sub "${applicationName}-gateway-policy"
PolicyDocument:
Version: "2012-10-17"
Statement:
- Sid: LambdaPermissions
Effect: Allow
Action:
- "lambda:InvokeFunction"
Resource:
- !GetAtt AuthorizeLambda.Arn
ManagedPolicyArns:
- arn:aws:iam::aws:policy/service-role/AmazonAPIGatewayPushToCloudWatchLogs
RoleName: !Sub ${applicationName}-apigateway-executor
Tags:
- Key: "Application"
Value: !Ref applicationName
AuthorizeLambda:
Type: AWS::Lambda::Function
Properties:
Description: !Sub Lambda for authorizing ${applicationName} administrators
FunctionName: !Sub ${applicationName}-authorize
Code:
ImageUri: docker.io/chinchalinchin/lambda-authorize:latest
PackageType: Image
Role: <lambda-execution-role-arn>
Timeout: 60
Environment:
Variables:
REGION: <aws-region>
USERPOOL_ID: <cognito-userpool-id>
CLIENT_ID: <cognito-client-id>
API_ID: <apigateway-rest-api-id>
ACCOUNT_ID: <aws-account-id>
GROUP: <cognito-gropu>
Tags:
- Key: "Application"
Value: !Ref applicationName
- Key: "Trigger"
Value: "apigateway"
ApiGatewayAdminAuthorizer:
Type: AWS::ApiGateway::Authorizer
Properties:
RestApiId: !Ref RestAPI
Name: !Sub ${applicationName}-api-admin-authorizer
Type: CUSTOM
IdentitySource: method.request.header.authorization
AuthorizerCredentials: !GetAtt APIExecutorRole.Arn
AuthorizerUri:
!Sub 'arn:aws:apigateway:${AWS::Region}:lambda:path/2015-03-31/functions/${AuthorizeLambda.Arn}/invocations'
Type: TOKEN
Content type
Image
Digest
Size
179.1 MB
Last updated
over 4 years ago
docker pull chinchalinchin/lambda-authorize