You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过API Gateway OpenAPI向REQUEST型Lambda授权器传自定义变量

API Gateway OpenAPI传递自定义变量给REQUEST类型Lambda授权器

背景

需要将类似roles: ["ROLE_ORDER_READ", "ROLE_ORDER_WRITE"]的自定义变量从API Gateway OpenAPI传递给REQUEST类型的Lambda授权器,不确定是否需要字符串化,若需要可自行处理。

当前OpenAPI定义

openapi: 3.0.0
paths:
  /api/v1/contacts/{id}/orders:
    get:
      x-amazon-apigateway-integration:
        type: aws_proxy
        uri: arn:$${AWS::Partition}:apigateway:$${AWS::Region}:lambda:path/2015-03-31/functions/${lambda_get_order_arn}/invocations
        httpMethod: POST
      security:
        - lambda_authorizer: []

期望配置(原写法不可行)

openapi: 3.0.0
paths:
  /api/v1/contacts/{id}/orders:
    get:
      x-amazon-apigateway-integration:
        type: aws_proxy
        uri: arn:$${AWS::Partition}:apigateway:$${AWS::Region}:lambda:path/2015-03-31/functions/${lambda_get_order_arn}/invocations
        httpMethod: POST
        # 期望添加的配置
        customVariables:
            roles: ["ROLE_ORDER_READ", "ROLE_ORDER_WRITE"]
      security:
        - lambda_authorizer: []

问题

  1. 如何通过OpenAPI实现该需求?是否有特定的x-amazon-apigateway-XXX扩展可用?
  2. 如何在Lambda授权器的event或context参数中访问这个自定义roles变量?

解答

问题1:OpenAPI配置实现方式

可以通过x-amazon-apigateway-integration扩展的context字段实现,API Gateway要求上下文变量为字符串类型,因此需要将数组格式的roles转换为字符串化的JSON。同时需确保已在components/securitySchemes中正确定义REQUEST类型的Lambda授权器。

修改后的有效配置示例:

openapi: 3.0.0
components:
  securitySchemes:
    lambda_authorizer:
      type: apiKey
      name: Authorization
      in: header
      x-amazon-apigateway-authtype: custom
      x-amazon-apigateway-authorizer:
        type: request
        uri: arn:$${AWS::Partition}:apigateway:$${AWS::Region}:lambda:path/2015-03-31/functions/${lambda_authorizer_arn}/invocations
        identitySource: method.request.header.Authorization
paths:
  /api/v1/contacts/{id}/orders:
    get:
      x-amazon-apigateway-integration:
        type: aws_proxy
        uri: arn:$${AWS::Partition}:apigateway:$${AWS::Region}:lambda:path/2015-03-31/functions/${lambda_get_order_arn}/invocations
        httpMethod: POST
        # 自定义上下文变量,需字符串化JSON
        context:
          roles: '["ROLE_ORDER_READ", "ROLE_ORDER_WRITE"]'
      security:
        - lambda_authorizer: []

问题2:Lambda授权器中访问自定义变量

自定义的roles变量会被传入授权器的event参数,位于event.requestContext.integration.context路径下,需将字符串化的JSON解析为数组使用。

示例代码(Python):

import json

def lambda_handler(event, context):
    # 获取字符串化的roles
    roles_str = event["requestContext"]["integration"]["context"]["roles"]
    # 解析为数组
    roles = json.loads(roles_str)
    
    # 此处编写授权逻辑,比如验证用户是否拥有对应角色
    # ...
    
    return {
        "principalId": "authorized-user",
        "policyDocument": {
            "Version": "2012-10-17",
            "Statement": [
                {
                    "Action": "execute-api:Invoke",
                    "Effect": "Allow",
                    "Resource": event["methodArn"]
                }
            ]
        }
    }

示例代码(Node.js):

exports.handler = async (event) => {
    const rolesStr = event.requestContext.integration.context.roles;
    const roles = JSON.parse(rolesStr);
    
    // 授权逻辑编写
    // ...
    
    return {
        principalId: "authorized-user",
        policyDocument: {
            Version: "2012-10-17",
            Statement: [{
                Action: "execute-api:Invoke",
                Effect: "Allow",
                Resource: event.methodArn
            }]
        }
    };
};

内容的提问来源于stack exchange,提问作者gokan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.22 07:47:33