Review authorization for an API Gateway REST API

Apply appropriate authentication and authorization to protected API operations.

Description

If a protected API operation lacks caller verification and permission checks, it may process unauthenticated or unauthorized requests. API Gateway REST APIs support controls such as Lambda or Cognito authorizers and IAM authentication.

An absent authorizer does not prove that other authentication is missing. Distinguish intentionally public operations and verify that a declared security scheme is actually applied to the relevant operations.

Potential impact

  • Unauthorized calls may reach sensitive data or functions.
  • Inconsistent authentication across paths can leave a new operation unintentionally public.

Remediation

Define which operations are public and the caller permissions required elsewhere, then apply an appropriate authorizer or IAM authentication. When importing OpenAPI, check the security schemes, operation security requirements and actual AWS authentication configuration together. Test that authorized calls succeed and calls with missing tokens or insufficient permissions are rejected.

Examples

The first excerpt shows part of an OpenAPI security scheme; the second imports an external specification. A complete API’s info, paths, integrations and authentication application are omitted.

Before

yaml
- name: Setup AWS API Gateway
  community.aws.aws_api_gateway:
    swagger_dict:
      {
        "openapi": "3.0.0",
        "components": {
          "securitySchemes": {
            "request_authorizer_single_stagevar": {
              "type": "apiKey",
              "name": "Unused",
              "in": "header"
            }
          }
        }
      }
    stage: production
    endpoint_type: EDGE
    state: present

This only declares an apiKey scheme. The declaration alone neither configures an AWS authorizer nor applies authentication to an operation.

After

yaml
- name: Setup AWS API Gateway
  community.aws.aws_api_gateway:
    swagger_file: swaggerFile.yaml
    stage: production
    endpoint_type: EDGE
    state: present

This imports swaggerFile.yaml. Using a file does not guarantee authentication; inspect its contents and the deployed API configuration.

References