You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用OpenAPI定义API Gateway授权器部署后不显示的问题

问题描述

尝试通过OpenAPI Specification定义授权器并关联到API的POST方法,但部署CloudFormation模板后,授权器未在API Gateway控制台显示,也未关联到目标POST方法。简化后的模板如下:

Type: AWS::Serverless::Api
Properties:
  Name: !Sub \"API Gateway\"
  EndpointConfiguration:
    Type: REGIONAL
  DefinitionBody:
    openapi: 3.0.3
    info:
      title: 'APIs'
      version: 1.0.0
    paths:
      /callHistoryAsync:
        post:
          parameters:
          - name: 'xxxxx'
            in: 'query'
            required: true
            schema:
              type: 'string'
          x-amazon-apigateway-integration:
            type: aws
            requestParameters:
              integration.request.header.X-Amz-Invocation-Type: '''Event'''
              integration.request.querystring.store_id: \"method.request.querystring.xxxxx\"
            httpMethod: POST
            uri: !Sub 'arn:${AWS::Partition}:apigateway:${AWS::Region}:lambda:path/2015-03-31/functions/${Function.Arn}/invocations'
            responses:
              '202':
                statusCode: '202'
                selectionPattern: \"\"
          responses:
            '202':
              description: successfully saved
          security:
            - Authorizer: []
 
    components:
      securitySchemes:
        Authorizer:
          type: 'request'
          name: 'Authorization'
          in: 'header'
          x-amazon-apigateway-authorizer:
            authorizerUri: !FindInMap [ !Ref StageName, !Ref \"AWS::Region\", AuthArn ]
            identitySource: 'method.request.header.X-Authorization,method.request.header.X-Date'
            type: 'request'
问题排查与修复

你的模板存在几个关键问题,导致授权器无法正常创建和关联:

  • 请求头名称不匹配
    你在securitySchemes中定义的name: 'Authorization',但identitySource里指定的身份来源是X-Authorization,API Gateway会根据name字段匹配请求头,名称不一致会导致授权器无法正确识别身份信息。需将name改为X-Authorization,或把identitySource中的对应字段改为Authorization,保持两者一致。

  • 授权器配置缺失必要项
    对于请求类型的授权器,建议明确添加authorizerResultTtlInSeconds(缓存过期时间,可选但能优化性能);更关键的是,要确保授权器Lambda函数拥有被API Gateway调用的权限——需额外配置AWS::Lambda::Permission资源,否则API Gateway无法触发授权器。

  • 模板转义字符异常
    模板中存在多余的转义字符(如\"),YAML格式下不需要对双引号转义,这会导致CloudFormation解析模板时出现异常。例如Name: !Sub \"API Gateway\"应改为Name: !Sub "API Gateway",selectionPattern: \"\"改为selectionPattern: ""。

  • 授权器Lambda权限配置
    必须为授权器Lambda添加权限,允许API Gateway调用它,示例配置如下:

    AuthLambdaInvokePermission:
      Type: AWS::Lambda::Permission
      Properties:
        FunctionName: !Ref AuthFunction
        Action: lambda:InvokeFunction
        Principal: apigateway.amazonaws.com
        SourceArn: !Sub 'arn:${AWS::Partition}:execute-api:${AWS::Region}:${AWS::AccountId}:${ServerlessApi}/*/POST/callHistoryAsync'
    

修复后的securitySchemes核心部分示例:

components:
  securitySchemes:
    Authorizer:
      type: 'request'
      name: 'X-Authorization'  # 与identitySource中的请求头名称统一
      in: 'header'
      x-amazon-apigateway-authorizer:
        authorizerUri: !FindInMap [ !Ref StageName, !Ref "AWS::Region", AuthArn ]
        identitySource: 'method.request.header.X-Authorization,method.request.header.X-Date'
        type: 'request'
        authorizerResultTtlInSeconds: 300  # 设置授权结果缓存时间

内容的提问来源于stack exchange,提问作者elena

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.02 15:50:31