Description
With aws_api_gateway_method.authorization = "NONE", API Gateway does not authenticate callers for the method. If a protected function also lacks other controls, unintended callers may read data or perform operations.
Unauthenticated methods can be appropriate for public content or CORS preflight requests. Resource policies and backend authentication and authorization also affect access; an OPTIONS response does not protect other methods.
Potential impact
- Protected functions may be called without the required permissions.
- Read APIs can expose data that should remain restricted.
- Abuse of write APIs can increase costs or alter data.
Remediation
- Review whether each method needs public access. Use appropriate authentication for protected methods, such as IAM, Cognito or a Lambda authorizer.
- Limit authenticated callers’ operation permissions and deploy changes to the actual stage.
- For intentionally public APIs, configure suitable access policies, usage limits and audit logs.
Examples
These excerpts compare authentication for the same GET method. Configure the API, resource, integration, Lambda authorizer and invocation permissions separately.
Before
hcl
resource "aws_api_gateway_method" "example" {
rest_api_id = aws_api_gateway_rest_api.this.id
resource_id = aws_api_gateway_resource.this.id
http_method = "GET"
authorization = "NONE"
request_parameters = {
"method.request.path.proxy" = true
}
}
After
hcl
resource "aws_api_gateway_method" "example" {
rest_api_id = aws_api_gateway_rest_api.this.id
resource_id = aws_api_gateway_resource.this.id
http_method = "GET"
authorization = "CUSTOM"
authorizer_id = aws_api_gateway_authorizer.this.id
request_parameters = {
"method.request.path.proxy" = true
}
}
Explanation:
- Before:
GETdoes not use API Gateway caller authentication. Check resource policies and backend controls as well. - After:
CUSTOMauthentication and an authorizer are attached to the sameGET. Verify that allowed calls succeed and unauthorized calls are denied.