如何通过API Gateway OpenAPI向REQUEST型Lambda授权器传自定义变量
API Gateway OpenAPI传递自定义变量给REQUEST类型Lambda授权器
背景
需要将类似roles: ["ROLE_ORDER_READ", "ROLE_ORDER_WRITE"]的自定义变量从API Gateway OpenAPI传递给REQUEST类型的Lambda授权器,不确定是否需要字符串化,若需要可自行处理。
当前OpenAPI定义
openapi: 3.0.0 paths: /api/v1/contacts/{id}/orders: get: x-amazon-apigateway-integration: type: aws_proxy uri: arn:$${AWS::Partition}:apigateway:$${AWS::Region}:lambda:path/2015-03-31/functions/${lambda_get_order_arn}/invocations httpMethod: POST security: - lambda_authorizer: []
期望配置(原写法不可行)
openapi: 3.0.0 paths: /api/v1/contacts/{id}/orders: get: x-amazon-apigateway-integration: type: aws_proxy uri: arn:$${AWS::Partition}:apigateway:$${AWS::Region}:lambda:path/2015-03-31/functions/${lambda_get_order_arn}/invocations httpMethod: POST # 期望添加的配置 customVariables: roles: ["ROLE_ORDER_READ", "ROLE_ORDER_WRITE"] security: - lambda_authorizer: []
问题
- 如何通过OpenAPI实现该需求?是否有特定的
x-amazon-apigateway-XXX扩展可用? - 如何在Lambda授权器的
event或context参数中访问这个自定义roles变量?
解答
问题1:OpenAPI配置实现方式
可以通过x-amazon-apigateway-integration扩展的context字段实现,API Gateway要求上下文变量为字符串类型,因此需要将数组格式的roles转换为字符串化的JSON。同时需确保已在components/securitySchemes中正确定义REQUEST类型的Lambda授权器。
修改后的有效配置示例:
openapi: 3.0.0 components: securitySchemes: lambda_authorizer: type: apiKey name: Authorization in: header x-amazon-apigateway-authtype: custom x-amazon-apigateway-authorizer: type: request uri: arn:$${AWS::Partition}:apigateway:$${AWS::Region}:lambda:path/2015-03-31/functions/${lambda_authorizer_arn}/invocations identitySource: method.request.header.Authorization paths: /api/v1/contacts/{id}/orders: get: x-amazon-apigateway-integration: type: aws_proxy uri: arn:$${AWS::Partition}:apigateway:$${AWS::Region}:lambda:path/2015-03-31/functions/${lambda_get_order_arn}/invocations httpMethod: POST # 自定义上下文变量,需字符串化JSON context: roles: '["ROLE_ORDER_READ", "ROLE_ORDER_WRITE"]' security: - lambda_authorizer: []
问题2:Lambda授权器中访问自定义变量
自定义的roles变量会被传入授权器的event参数,位于event.requestContext.integration.context路径下,需将字符串化的JSON解析为数组使用。
示例代码(Python):
import json def lambda_handler(event, context): # 获取字符串化的roles roles_str = event["requestContext"]["integration"]["context"]["roles"] # 解析为数组 roles = json.loads(roles_str) # 此处编写授权逻辑,比如验证用户是否拥有对应角色 # ... return { "principalId": "authorized-user", "policyDocument": { "Version": "2012-10-17", "Statement": [ { "Action": "execute-api:Invoke", "Effect": "Allow", "Resource": event["methodArn"] } ] } }
示例代码(Node.js):
exports.handler = async (event) => { const rolesStr = event.requestContext.integration.context.roles; const roles = JSON.parse(rolesStr); // 授权逻辑编写 // ... return { principalId: "authorized-user", policyDocument: { Version: "2012-10-17", Statement: [{ Action: "execute-api:Invoke", Effect: "Allow", Resource: event.methodArn }] } }; };
内容的提问来源于stack exchange,提问作者gokan
相关产品推荐
相关产品推荐

