Description
Without effective authentication and authorization on protected REST API methods, unintended callers may use their functions. IAM authentication or other controls may apply even without an Authorizer resource, so check the actual method settings.
Declaring a Lambda or Cognito authorizer does not protect a method by itself. It must reference the intended REST API, and the method’s authorization and authorizer_id must be configured correctly.
Potential impact
- Caller verification can be applied inconsistently.
- Functions intended to be protected may be exposed.
- Inconsistent authentication choices can complicate operations.
Remediation
- Choose authentication appropriate for the service. If using an authorizer, configure
aws_api_gateway_authorizerfor the target REST API. - On the method, use
CUSTOMfor a Lambda authorizer orCOGNITO_USER_POOLSfor Cognito, with the correspondingauthorizer_id. Configure necessary invocation permissions. - Verify that the authorizer and method authorization work together before deployment.
Examples
These excerpts show only the API-to-Lambda-authorizer association. The Lambda function, invocation role and method settings are omitted. The demo API referenced in the first example is assumed to exist separately.
Before
resource "aws_api_gateway_authorizer" "demo" {
name = "demo"
rest_api_id = aws_api_gateway_rest_api.demo.id
authorizer_uri = aws_lambda_function.authorizer.invoke_arn
authorizer_credentials = aws_iam_role.invocation_role.arn
}
resource "aws_api_gateway_rest_api" "demo2" {
name = "auth-demo"
}
After
resource "aws_api_gateway_authorizer" "demo" {
name = "demo"
rest_api_id = aws_api_gateway_rest_api.demo.id
authorizer_uri = aws_lambda_function.authorizer.invoke_arn
authorizer_credentials = aws_iam_role.invocation_role.arn
}
resource "aws_api_gateway_rest_api" "demo" {
name = "auth-demo"
}
Explanation:
- Before: The authorizer references a different REST API and does not protect the shown API.
- After: The authorizer references the shown API. Attach its authentication type and ID to the method as well, then test allowed and denied requests.