Review API Gateway method authentication

Apply caller authentication and required permission checks to API Gateway methods that need protection.

Description

With aws_api_gateway_method.authorization = "NONE", API Gateway does not authenticate callers for the method. If a protected function also lacks other controls, unintended callers may read data or perform operations.

Unauthenticated methods can be appropriate for public content or CORS preflight requests. Resource policies and backend authentication and authorization also affect access; an OPTIONS response does not protect other methods.

Potential impact

  • Protected functions may be called without the required permissions.
  • Read APIs can expose data that should remain restricted.
  • Abuse of write APIs can increase costs or alter data.

Remediation

  • Review whether each method needs public access. Use appropriate authentication for protected methods, such as IAM, Cognito or a Lambda authorizer.
  • Limit authenticated callers’ operation permissions and deploy changes to the actual stage.
  • For intentionally public APIs, configure suitable access policies, usage limits and audit logs.

Examples

These excerpts compare authentication for the same GET method. Configure the API, resource, integration, Lambda authorizer and invocation permissions separately.

Before

hcl
resource "aws_api_gateway_method" "example" {
  rest_api_id   = aws_api_gateway_rest_api.this.id
  resource_id   = aws_api_gateway_resource.this.id
  http_method   = "GET"
  authorization = "NONE"

  request_parameters = {
    "method.request.path.proxy" = true
  }
}

After

hcl
resource "aws_api_gateway_method" "example" {
  rest_api_id   = aws_api_gateway_rest_api.this.id
  resource_id   = aws_api_gateway_resource.this.id
  http_method   = "GET"
  authorization = "CUSTOM"
  authorizer_id = aws_api_gateway_authorizer.this.id

  request_parameters = {
    "method.request.path.proxy" = true
  }
}

Explanation:

  • Before: GET does not use API Gateway caller authentication. Check resource policies and backend controls as well.
  • After: CUSTOM authentication and an authorizer are attached to the same GET. Verify that allowed calls succeed and unauthorized calls are denied.

References