You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在Serverless的API Gateway配置中添加安全报头失败:无效配置

问题描述

我通过Serverless框架部署多个由API Gateway触发的Lambda函数,尝试在serverless.yml的provider.apiGateway段配置全局安全头,但收到警告:

Warning: Invalid configuration encountered
at 'provider.apiGateway': unrecognized property 'response'

我的配置片段如下:
serverless.yml

service: my-service
provider:
  name: aws
  runtime: nodejs14.x
  stage: dev
  region: us-east-1
  profile: xyz
  apiGateway:
    restApiId: # 可指定现有API Gateway ID
    restApiRootResourceId: # 可指定现有根资源ID
    response:
      headers:
        Strict-Transport-Security: "'max-age=31536000; includeSubDomains'"

functions:
  helloWorld:
    handler: handler.hello
    events:
      - http:
          path: 'hello'
          method: get
          cors: true

handler.js

'use strict';

module.exports.hello = async (event) => {
  return {
    statusCode: 500,
    error: 'Error'
  };
};

请问如何在API Gateway全局配置中添加安全头,避免为每个函数单独配置?

解决方案

Serverless框架的provider.apiGateway配置段并不支持response属性,因此会触发无效配置警告。要全局添加安全头,推荐以下两种方法:

方法1:通过CloudFormation自定义资源配置全局响应头

利用Serverless支持CloudFormation资源的特性,定义AWS::ApiGateway::GatewayResponse资源,针对API Gateway的所有响应类型(成功响应、错误响应等)统一添加安全头。

修改serverless.yml,添加Resources段:

service: my-service
provider:
  name: aws
  runtime: nodejs14.x
  stage: dev
  region: us-east-1
  profile: xyz
  apiGateway:
    restApiId: # 可指定现有API Gateway ID
    restApiRootResourceId: # 可指定现有根资源ID

functions:
  helloWorld:
    handler: handler.hello
    events:
      - http:
          path: 'hello'
          method: get
          cors: true

resources:
  Resources:
    # 针对2XX成功响应添加安全头
    GatewayResponseDefault2XX:
      Type: 'AWS::ApiGateway::GatewayResponse'
      Properties:
        ResponseParameters:
          gatewayresponse.header.Strict-Transport-Security: "'max-age=31536000; includeSubDomains'"
          gatewayresponse.header.X-Content-Type-Options: "'nosniff'"
          gatewayresponse.header.X-Frame-Options: "'DENY'"
        ResponseType: DEFAULT_2XX
        RestApiId:
          Ref: ApiGatewayRestApi
    # 针对4XX客户端错误响应添加安全头
    GatewayResponseDefault4XX:
      Type: 'AWS::ApiGateway::GatewayResponse'
      Properties:
        ResponseParameters:
          gatewayresponse.header.Strict-Transport-Security: "'max-age=31536000; includeSubDomains'"
          gatewayresponse.header.X-Content-Type-Options: "'nosniff'"
          gatewayresponse.header.X-Frame-Options: "'DENY'"
        ResponseType: DEFAULT_4XX
        RestApiId:
          Ref: ApiGatewayRestApi
    # 针对5XX服务端错误响应添加安全头
    GatewayResponseDefault5XX:
      Type: 'AWS::ApiGateway::GatewayResponse'
      Properties:
        ResponseParameters:
          gatewayresponse.header.Strict-Transport-Security: "'max-age=31536000; includeSubDomains'"
          gatewayresponse.header.X-Content-Type-Options: "'nosniff'"
          gatewayresponse.header.X-Frame-Options: "'DENY'"
        ResponseType: DEFAULT_5XX
        RestApiId:
          Ref: ApiGatewayRestApi

这段配置会为API Gateway的2XX、4XX、5XX所有响应类型自动添加指定的安全头,无需为每个函数单独配置。

方法2:使用Serverless插件简化配置

如果不想手动编写CloudFormation资源,可以使用serverless-api-gateway-response插件:

  1. 安装插件:
npm install serverless-api-gateway-response --save-dev
  1. 在serverless.yml中配置插件和全局响应头:
service: my-service
provider:
  name: aws
  runtime: nodejs14.x
  stage: dev
  region: us-east-1
  profile: xyz
  apiGateway:
    restApiId: # 可指定现有API Gateway ID
    restApiRootResourceId: # 可指定现有根资源ID

plugins:
  - serverless-api-gateway-response

custom:
  apiGatewayResponse:
    headers:
      Strict-Transport-Security: "'max-age=31536000; includeSubDomains'"
      X-Content-Type-Options: "'nosniff'"
      X-Frame-Options: "'DENY'"
    responses:
      DEFAULT_2XX:
        statusCode: 200
      DEFAULT_4XX:
        statusCode: 400
      DEFAULT_5XX:
        statusCode: 500

functions:
  helloWorld:
    handler: handler.hello
    events:
      - http:
          path: 'hello'
          method: get
          cors: true

插件会自动生成对应的CloudFormation资源,实现全局响应头的统一配置。

内容的提问来源于stack exchange,提问作者karPower

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.15 08:12:52