自定义授权者 AWS CDK

Las*_*apa 5 amazon-web-services aws-api-gateway aws-cdk

我正在尝试使用 CDK 将自定义授权者附加到 API。

我正在使用 Cognito 进行用户管理。

我想通过自定义授权者实现的是,

  • 检查用户是否有使用API​​的权限
  • 识别用户的电子邮件 (userId) 并将其附加到请求正文
  • 在 API lambda 中使用该电子邮件

我找不到任何有关如何将自定义授权者附加到 API 的示例或文档。如何附加自定义授权者,或者如果 CDK 不支持它,是否有解决方法来满足要求?

amw*_*l04 3

以下内容可能会帮助您实现您想要的目标。目前authorizer尚未addMethod实现,因此您需要覆盖。

const api = new RestApi(this, 'RestAPI', {
    restApiName: 'Rest-Name',
    description: 'API for journey services.',
});

const putIntegration = new LambdaIntegration(handler);

const auth = new CfnAuthorizer(this, 'CustomAuthorizer', {
    name: 'custom-authorizer',
    type: AuthorizationType.CUSTOM,
    ...
});

const post = api.root.addMethod('PUT', putIntegration, { authorizationType: AuthorizationType.CUSTOM });
const postMethod = post.node.defaultChild as CfnMethod;
postMethod.addOverride('Properties.AuthorizerId', { Ref: auth.logicalId });
Run Code Online (Sandbox Code Playgroud)

这会附加创建的authorizer

  • 嘿,现在 `addMethod` 上有一个 `authorizer` 选项: api.root.addMethod('PUT', putIntegration, {authorizationType: AuthorizationType.CUSTOM,authorizer: {authorizerId:authorizer.ref } } (2认同)