Review API Gateway REST API authentication

Attach suitable authentication to protected REST API methods and verify actual permission checks.

Description

Without effective authentication and authorization on protected REST API methods, unintended callers may use their functions. IAM authentication or other controls may apply even without an Authorizer resource, so check the actual method settings.

Declaring a Lambda or Cognito authorizer does not protect a method by itself. It must reference the intended REST API, and the method’s authorization and authorizer_id must be configured correctly.

Potential impact

  • Caller verification can be applied inconsistently.
  • Functions intended to be protected may be exposed.
  • Inconsistent authentication choices can complicate operations.

Remediation

  • Choose authentication appropriate for the service. If using an authorizer, configure aws_api_gateway_authorizer for the target REST API.
  • On the method, use CUSTOM for a Lambda authorizer or COGNITO_USER_POOLS for Cognito, with the corresponding authorizer_id. Configure necessary invocation permissions.
  • Verify that the authorizer and method authorization work together before deployment.

Examples

These excerpts show only the API-to-Lambda-authorizer association. The Lambda function, invocation role and method settings are omitted. The demo API referenced in the first example is assumed to exist separately.

Before

hcl
resource "aws_api_gateway_authorizer" "demo" {
  name                   = "demo"
  rest_api_id            = aws_api_gateway_rest_api.demo.id
  authorizer_uri         = aws_lambda_function.authorizer.invoke_arn
  authorizer_credentials = aws_iam_role.invocation_role.arn
}

resource "aws_api_gateway_rest_api" "demo2" {
  name = "auth-demo"
}

After

hcl
resource "aws_api_gateway_authorizer" "demo" {
  name                   = "demo"
  rest_api_id            = aws_api_gateway_rest_api.demo.id
  authorizer_uri         = aws_lambda_function.authorizer.invoke_arn
  authorizer_credentials = aws_iam_role.invocation_role.arn
}

resource "aws_api_gateway_rest_api" "demo" {
  name = "auth-demo"
}

Explanation:

  • Before: The authorizer references a different REST API and does not protect the shown API.
  • After: The authorizer references the shown API. Attach its authentication type and ID to the method as well, then test allowed and denied requests.

References