Sign inSign up

chinchalinchin/lambda-authorize

By chinchalinchin

•Updated over 4 years ago

AWS Lambda function for authorizing requests to an API Gateway via a Cognito User Pool.

Image
0

352

chinchalinchin/lambda-authorize repository overview

⁠Authorize Lambda

This is a AWS Lambda function for authorizing requests to an API Gateway through a Cognito Userpool. This function will decode a Cognito JWT token⁠ in a request's Authorization header and then return a policy statement⁠ to inform API Gateway whether or not the incoming request is authorized to access the resource.

See documentation for more information on using a Lambda authorizer in an API Gateway⁠.

The source code for this Lambda can be found here⁠.

⁠Configuration

⁠Environment Variables

The following variables need delivered to the Lambda execution environment.

  1. ACCOUNT_ID: Identification number for AWS account.

  2. API_ID: Physical identification number for API Gateway REST API deployment.

  3. USERPOOL_ID: Cognito Userpool identification number.

  4. CLIENT_ID: Physicacl identification number for the Cognito Client.

  5. REGION: Region where the API gateway is hosted.

  6. GROUP: Optional. If GROUP is specified, the user associated with incoming request must belong to the specified group name, found in the cognito:groups property in the JWT payload. If the user does not belong to this group, request will be rejected. If GROUP is not specified, function will only validate the authenticity of the JWT.

⁠Infrastructure-as-Code

There are several resources needed to hook this function into an existing API Gateway. The API Gateway authorizer will need an execution role attached to it, with permission invoke the Lambda function, so this role will need created, if it does not already exist.

The following CloudFormation template will provision the IAM role for the gateway authorizer to attach, the API Gateway authorizer and the Lambda function that gets invoked as the authorizer.


NOTE : <> indicate this value needs replaced.


AWSTemplateFormatVersion: '2010-09-09'

Parameters:
  applicationName:
    Type: String
    Description: Application namespace where resources are being deployed
    Default: demo

Resources:
    APIExecutorRole:
        Type: AWS::IAM::Role
        Properties:
            Description: !Sub Assumed role for API Gateway to accecss ${applicationName} resources.
            Path: !Sub "/${applicationName}/"
            AssumeRolePolicyDocument:
            Version: "2012-10-17"
            Statement:
                - Effect: Allow
                Principal:
                    Service:
                    - apigateway.amazonaws.com
                Action:
                    - "sts:AssumeRole"
            Policies:
            - PolicyName: !Sub "${applicationName}-gateway-policy"
                PolicyDocument:
                Version: "2012-10-17"
                Statement:
                    - Sid: LambdaPermissions
                    Effect: Allow
                    Action: 
                        - "lambda:InvokeFunction"
                    Resource: 
                        - !GetAtt AuthorizeLambda.Arn
            ManagedPolicyArns:
            - arn:aws:iam::aws:policy/service-role/AmazonAPIGatewayPushToCloudWatchLogs
            RoleName: !Sub ${applicationName}-apigateway-executor
            Tags:
            - Key: "Application"
                Value: !Ref applicationName

    AuthorizeLambda:
        Type: AWS::Lambda::Function
        Properties:
        Description: !Sub Lambda for authorizing ${applicationName} administrators
        FunctionName: !Sub ${applicationName}-authorize
        Code:
            ImageUri: docker.io/chinchalinchin/lambda-authorize:latest
        PackageType: Image
        Role: <lambda-execution-role-arn>
        Timeout: 60
        Environment:
            Variables:
                REGION: <aws-region>
                USERPOOL_ID: <cognito-userpool-id>
                CLIENT_ID: <cognito-client-id>
                API_ID: <apigateway-rest-api-id>
                ACCOUNT_ID: <aws-account-id>
                GROUP: <cognito-gropu>
        Tags:
            - Key: "Application"
            Value: !Ref applicationName
            - Key: "Trigger"
            Value: "apigateway"

    ApiGatewayAdminAuthorizer:
        Type: AWS::ApiGateway::Authorizer
        Properties:
        RestApiId: !Ref RestAPI
        Name: !Sub ${applicationName}-api-admin-authorizer
        Type: CUSTOM
        IdentitySource: method.request.header.authorization
        AuthorizerCredentials: !GetAtt APIExecutorRole.Arn
        AuthorizerUri: 
            !Sub 'arn:aws:apigateway:${AWS::Region}:lambda:path/2015-03-31/functions/${AuthorizeLambda.Arn}/invocations'
        Type: TOKEN

Tag summary

Content type

Image

Digest

Size

179.1 MB

Last updated

over 4 years ago

docker pull chinchalinchin/lambda-authorize