API Gateway REST API policy grants excessive access

Limit REST API resource policies to the required callers, actions, and API paths.

Description

A REST API resource policy that grants broad invocation permissions to every principal can allow unintended access. Effective access also depends on method authentication, authorization, and other applicable policies; a public grant alone does not establish an authentication bypass.

Potential impact

  • Unapproved clients may invoke the API when the effective access controls permit it.
  • Excessive requests can misuse backend functions and increase costs or service load.

Remediation

Allow only required callers and execute-api:Invoke. Set Resource to the actual API execution ARN and required stage, method, and path. Apply relevant conditions and test both approved and unwanted requests together with method authentication.

Examples

These are resource-policy excerpts. Configure the referenced API separately and replace the account, user, path, and IP address with approved values. Requests from the IAM user in the revised example require AWS_IAM method authentication and SigV4 signing.

Before

hcl
resource "aws_api_gateway_rest_api_policy" "example" {
  rest_api_id = aws_api_gateway_rest_api.api_gw.id

  policy = <<EOF
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": {
        "AWS": "*"
      },
      "Action": "execute-api:*",
      "Resource": "${aws_api_gateway_rest_api.api_gw.execution_arn}/*/*/*"
    }
  ]
}
EOF
}

After

hcl
resource "aws_api_gateway_rest_api_policy" "example" {
  rest_api_id = aws_api_gateway_rest_api.api_gw.id

  policy = <<EOF
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": {
        "AWS": [
          "arn:aws:iam::123456789012:user/test-user"
        ]
      },
      "Action": "execute-api:Invoke",
      "Resource": "${aws_api_gateway_rest_api.api_gw.execution_arn}/prod/GET/orders",
      "Condition": {
        "IpAddress": {
          "aws:SourceIp": "123.123.123.123/32"
        }
      }
    }
  ]
}
EOF
}

The revised policy narrows the grant to one user, GET /orders, and a source IP. Review other applicable policies and the actual method configuration as well.

References