Description
API response caches can store query results and related data. Without cache encryption, stored responses lack encryption-at-rest protection. This is especially relevant for APIs that handle user information or internal responses.
Configure data protection as well as performance when using a cache. Encryption does not prevent an incorrect cache key or access policy from returning another user’s response.
Potential impact
- Unauthorized access to cache storage can increase the risk of exposing sensitive response data.
- Organizational API-cache encryption requirements may not be met.
Remediation
- Explicitly set
cache_data_encrypted = truefor methods that use caching. - Cache only the methods that need it, and review sensitive data, cache keys and permissions.
- After applying the change, verify the stage cache and method encryption settings, and test normal response handling.
Examples
These excerpts reference a separately defined REST API and stage. The stage’s cache cluster must also be enabled for caching to operate.
Before
resource "aws_api_gateway_method_settings" "cached_method" {
rest_api_id = aws_api_gateway_rest_api.example.id
stage_name = aws_api_gateway_stage.example.stage_name
method_path = "path1/GET"
settings {
metrics_enabled = true
logging_level = "INFO"
caching_enabled = true
cache_data_encrypted = false
}
}
Method caching is enabled, but cache-data encryption is disabled.
After
resource "aws_api_gateway_method_settings" "cached_method" {
rest_api_id = aws_api_gateway_rest_api.example.id
stage_name = aws_api_gateway_stage.example.stage_name
method_path = "path1/GET"
settings {
metrics_enabled = true
logging_level = "INFO"
caching_enabled = true
cache_data_encrypted = true
}
}
This keeps caching enabled and adds encryption. Review which responses may be shared and the applicable permissions separately.