如何通过API Gateway发送自定义错误消息并修改DENY响应
在API Gateway中配置自定义DENY错误消息
要把API Gateway返回的默认DENY错误消息("User is not authorized to access this resource with an explicit deny")改成"Not allowed",可以通过配置**网关响应(Gateway Responses)**实现,以下是YAML模板的配置方式:
YAML模板配置示例
在CloudFormation模板中,通过AWS::ApiGateway::RestApi资源的GatewayResponses属性定义自定义的ACCESS_DENIED响应:
Resources: CustomRestApi: Type: AWS::ApiGateway::RestApi Properties: Name: YourApiName GatewayResponses: # 配置显式拒绝场景的自定义响应 ACCESS_DENIED: # 设置JSON格式的响应内容 ResponseTemplates: application/json: | {"message": "Not allowed"} # 指定响应的Content-Type头部 ResponseParameters: gatewayresponse.header.Content-Type: "'application/json'"
关键说明
ACCESS_DENIED类型对应IAM授权返回的显式拒绝场景,配置后所有此类场景的响应都会替换为自定义的"Not allowed"消息。- 若需支持其他内容类型(如
text/plain),可在ResponseTemplates中添加对应类型的模板内容。
内容的提问来源于stack exchange,提问作者Tanu
相关产品推荐
相关产品推荐

