Review API Gateway method authentication

Apply caller authentication and operation-specific permissions to methods that need protection.

Description

When an API Gateway method uses AuthorizationType NONE, API Gateway does not authenticate callers for that method. If a protected function has no other access controls, unintended callers may read data or perform operations.

Unauthenticated methods can be appropriate for public content or CORS preflight requests. Resource policies and backend authentication and authorization also affect access; an OPTIONS response does not protect other methods.

Potential impact

  • Sensitive read or modification functions may be invoked without the required permissions.
  • Abuse of public calls can increase backend load or costs.

Remediation

Confirm the public-access requirement of each method and configure suitable authentication for protected methods, such as AWS_IAM, Cognito or a Lambda authorizer. Restrict authenticated callers to the required actions and resources. Deploy changes to the actual stage and test that authorized calls succeed and unauthorized calls are denied.

Examples

These excerpts show different methods. API and integration settings are omitted. The later OPTIONS example does not add authentication to the earlier GET method.

Before

yaml
Resources:
  MockMethod:
    Type: AWS::ApiGateway::Method
    Properties:
      RestApiId: !Ref MyApi
      ResourceId: !GetAtt MyApi.RootResourceId
      HttpMethod: GET
      AuthorizationType: NONE

The GET method does not use API Gateway authentication. Review the functions it provides and other access controls.

After

yaml
Resources:
  CorsOptionsMethod:
    Type: AWS::ApiGateway::Method
    Properties:
      RestApiId: !Ref MyApi
      ResourceId: !GetAtt MyApi.RootResourceId
      HttpMethod: OPTIONS
      AuthorizationType: NONE

The OPTIONS method is also configured without authentication. It can support CORS preflight handling but does not remove or protect the GET method.

References