You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Lambda触发器无AppSync授权实现及DynamoDB直连API优化方案咨询

直接用Cognito授权Lambda操作DynamoDB的无AppSync方案

一、调整Lambda的IAM权限与信任策略

  1. 给Lambda执行角色添加DynamoDB操作权限
    直接在Lambda的IAM角色中配置目标DynamoDB表的读写权限,若需要用户只能操作自身数据,可结合Cognito用户的sub属性做细粒度控制:

    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Effect": "Allow",
          "Action": [
            "dynamodb:GetItem",
            "dynamodb:PutItem",
            "dynamodb:UpdateItem"
          ],
          "Resource": "arn:aws:dynamodb:REGION:ACCOUNT_ID:table/YOUR_TABLE_NAME",
          "Condition": {
            "StringEquals": {
              "dynamodb:LeadingKeys": "${cognito-identity.amazonaws.com:sub}"
            }
          }
        }
      ]
    }
    
  2. 配置Lambda信任策略,允许Cognito身份调用
    修改Lambda的IAM角色信任策略,仅允许Cognito身份池的认证用户触发Lambda:

    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Effect": "Allow",
          "Principal": {
            "Federated": "cognito-identity.amazonaws.com"
          },
          "Action": "sts:AssumeRoleWithWebIdentity",
          "Condition": {
            "StringEquals": {
              "cognito-identity.amazonaws.com:aud": "YOUR_COGNITO_IDENTITY_POOL_ID"
            },
            "ForAnyValue:StringLike": {
              "cognito-identity.amazonaws.com:amr": "authenticated"
            }
          }
        }
      ]
    }
    

二、前端直接调用Lambda(绕过AppSync)

利用Amplify Auth模块获取Cognito临时凭证,直接调用Lambda,完全跳过AppSync:

  1. 获取用户身份凭证

    import { Auth } from 'aws-amplify';
    
    const getCredentials = async () => {
      const credentials = await Auth.currentCredentials();
      return credentials;
    };
    
  2. 直接触发Lambda函数
    使用AWS SDK v3调用Lambda,传入用户凭证:

    import { LambdaClient, InvokeCommand } from "@aws-sdk/client-lambda";
    
    const invokeLambda = async (payload) => {
      const credentials = await getCredentials();
      const lambdaClient = new LambdaClient({
        region: "YOUR_REGION",
        credentials: {
          accessKeyId: credentials.accessKeyId,
          secretAccessKey: credentials.secretAccessKey,
          sessionToken: credentials.sessionToken
        }
      });
    
      const command = new InvokeCommand({
        FunctionName: "YOUR_LAMBDA_NAME",
        Payload: JSON.stringify(payload)
      });
    
      const response = await lambdaClient.send(command);
      return JSON.parse(Buffer.from(response.Payload).toString());
    };
    

三、Lambda内部的授权校验(可选但推荐)

在Lambda内添加额外校验,确保调用者是合法Cognito用户且拥有对应权限:

import boto3

def lambda_handler(event, context):
    # 获取用户身份ID
    identity_id = context.identity.cognito_identity_id
    
    # 校验用户所属分组(示例)
    cognito_client = boto3.client('cognito-idp')
    user_groups = cognito_client.admin_list_groups_for_user(
        UserPoolId='YOUR_USER_POOL_ID',
        Username=context.identity.cognito_authenticated_role.split('/')[-1]
    )
    
    if 'authorized_group' not in [g['GroupName'] for g in user_groups['Groups']]:
        return {'statusCode': 403, 'body': '无操作权限'}
    
    # 后续直接操作DynamoDB
    dynamodb = boto3.resource('dynamodb')
    table = dynamodb.Table('YOUR_TABLE_NAME')
    # ...业务逻辑处理

四、极端优化:前端直接操作DynamoDB(无Lambda)

若业务逻辑无需Lambda处理,可让前端直接操作DynamoDB:

  1. 在Cognito身份池的认证角色中添加DynamoDB权限(同Lambda权限配置逻辑)
  2. 前端直接调用DynamoDB:
    import { DynamoDBClient, PutItemCommand } from "@aws-sdk/client-dynamodb";
    import { marshall } from "@aws-sdk/util-dynamodb";
    
    const saveData = async (data) => {
      const credentials = await getCredentials();
      const ddbClient = new DynamoDBClient({
        region: "YOUR_REGION",
        credentials: credentials
      });
      const command = new PutItemCommand({
        TableName: "YOUR_TABLE_NAME",
        Item: marshall({ ...data, userId: credentials.identityId })
      });
      await ddbClient.send(command);
    };
    

关键注意事项

  • 权限最小化:所有IAM角色只赋予必要的操作权限,避免过度授权
  • 凭证安全:Amplify会自动管理临时凭证的刷新,无需手动处理过期问题
  • 日志监控:开启Lambda和DynamoDB的CloudWatch日志,方便排查权限或业务异常

内容的提问来源于stack exchange,提问作者Muhammad Arqam

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.22 04:37:46