Description
When an API Gateway method uses AuthorizationType NONE, API Gateway does not authenticate callers for that method. If a protected function has no other access controls, unintended callers may read data or perform operations.
Unauthenticated methods can be appropriate for public content or CORS preflight requests. Resource policies and backend authentication and authorization also affect access; an OPTIONS response does not protect other methods.
Potential impact
- Sensitive read or modification functions may be invoked without the required permissions.
- Abuse of public calls can increase backend load or costs.
Remediation
Confirm the public-access requirement of each method and configure suitable authentication for protected methods, such as AWS_IAM, Cognito or a Lambda authorizer. Restrict authenticated callers to the required actions and resources. Deploy changes to the actual stage and test that authorized calls succeed and unauthorized calls are denied.
Examples
These excerpts show different methods. API and integration settings are omitted. The later OPTIONS example does not add authentication to the earlier GET method.
Before
Resources:
MockMethod:
Type: AWS::ApiGateway::Method
Properties:
RestApiId: !Ref MyApi
ResourceId: !GetAtt MyApi.RootResourceId
HttpMethod: GET
AuthorizationType: NONE
The GET method does not use API Gateway authentication. Review the functions it provides and other access controls.
After
Resources:
CorsOptionsMethod:
Type: AWS::ApiGateway::Method
Properties:
RestApiId: !Ref MyApi
ResourceId: !GetAtt MyApi.RootResourceId
HttpMethod: OPTIONS
AuthorizationType: NONE
The OPTIONS method is also configured without authentication. It can support CORS preflight handling but does not remove or protect the GET method.