Description
If a protected API operation lacks caller verification and permission checks, it may process unauthenticated or unauthorized requests. API Gateway REST APIs support controls such as Lambda or Cognito authorizers and IAM authentication.
An absent authorizer does not prove that other authentication is missing. Distinguish intentionally public operations and verify that a declared security scheme is actually applied to the relevant operations.
Potential impact
- Unauthorized calls may reach sensitive data or functions.
- Inconsistent authentication across paths can leave a new operation unintentionally public.
Remediation
Define which operations are public and the caller permissions required elsewhere, then apply an appropriate authorizer or IAM authentication. When importing OpenAPI, check the security schemes, operation security requirements and actual AWS authentication configuration together. Test that authorized calls succeed and calls with missing tokens or insufficient permissions are rejected.
Examples
The first excerpt shows part of an OpenAPI security scheme; the second imports an external specification. A complete API’s info, paths, integrations and authentication application are omitted.
Before
- name: Setup AWS API Gateway
community.aws.aws_api_gateway:
swagger_dict:
{
"openapi": "3.0.0",
"components": {
"securitySchemes": {
"request_authorizer_single_stagevar": {
"type": "apiKey",
"name": "Unused",
"in": "header"
}
}
}
}
stage: production
endpoint_type: EDGE
state: present
This only declares an apiKey scheme. The declaration alone neither configures an AWS authorizer nor applies authentication to an operation.
After
- name: Setup AWS API Gateway
community.aws.aws_api_gateway:
swagger_file: swaggerFile.yaml
stage: production
endpoint_type: EDGE
state: present
This imports swaggerFile.yaml. Using a file does not guarantee authentication; inspect its contents and the deployed API configuration.