基于AWS API Gateway与SES的无服务器联系表单签名匹配错误排查
问题:API Gateway调用SES时出现SignatureDoesNotMatch错误
我在S3上搭建无服务器联系表单,通过API Gateway调用SES向收件人发送邮件,按教程操作后,API测试返回HTTP 200状态,但SES返回以下错误:
{"Error":{"Code":"SignatureDoesNotMatch","Message":"The request signature we calculated does not match the signature you provided. Check your AWS Secret Access Key and signing method. Consult the service documentation for details.","Type":"Sender"},"RequestId":"1559f1b5-7000-4fe5-9d70-38b729adba46"}
API测试完整执行栈
Execution log for request a18a0aa1-fa42-4bc8-a3c0-c6754716398f Fri Dec 02 20:19:12 UTC 2022 : Starting execution for request: a18a0aa1-fa42-4bc8-a3c0-c6754716398f Fri Dec 02 20:19:12 UTC 2022 : HTTP Method: POST, Resource Path: / Fri Dec 02 20:19:12 UTC 2022 : Method request path: {} Fri Dec 02 20:19:12 UTC 2022 : Method request query string: {} Fri Dec 02 20:19:12 UTC 2022 : Method request headers: {} Fri Dec 02 20:19:12 UTC 2022 : Method request body before transformations: { "name": "Test Name", "email": "test@test.com", "phone": "123-456-7890", "message": "This is a test message!" } Fri Dec 02 20:19:12 UTC 2022 : Endpoint request URI: https://email.us-east-1.amazonaws.com/SendEmail Fri Dec 02 20:19:12 UTC 2022 : Endpoint request headers: {Authorization=************************************************************************************************************************************************************************************************************************************************************************098c83, X-Amz-Date=20221202T201912Z, x-amzn-apigateway-api-id=1j6iefoiqj, Accept=application/json, User-Agent=AmazonAPIGateway_1j6iefoiqj, X-Amz-Security-Token=IQoJb3JpZ2luX2VjEJX//////////wEaCXVzLWVhc3QtMSJHMEUCIAVdXRcxBZlgf9mN9jqp6OxEtITF/KMl+MzbXyb89NZrAiEAzSxr6P0cIMDwGDkkXOYr1C2KINbRKN2X0zozBMh7fjIq7gIIrf//////////ARADGgwzMzc2MzIxMzUyNDQiDHpwxD6RfZw5uGjCHirCAse0l62z8auypaCu5K+bUgeCqsXqtE7bjBhct1ZG0WK5q5gw3DRKGLPmqPc9nFZ1pbeRUCw5LvuuI+6jQKs2CCJisZlgrGjSD/m1akgPkVsR1FtCNj6z7GEURaTg6r3aqz2KXyrHVft4cex+BoSOeMUMBBXWOKJirppkK8KGz4yNNPYFJ1BPLWQJcWOb6rPi/87pPoey0E3PiwLf1SXTVzkc/S/I/tpLzV7fARx4vheXC7c+SmAHyg/Zm318As5OBCqGBPXKpK0UT/7z4r9/vqDRzCsXXe0FCGJjOyMuM5y9k5bnsT5sRjpenX1DOkUopLoEsc2xTjunfEXKGmfn+M96I+Z3JbrnGMz [TRUNCATED] Fri Dec 02 20:19:12 UTC 2022 : Endpoint request body after transformations: Action=SendEmail&Message.Body.Text.Data=%0AName%3A+%22Test+Name%22%0AEmail%3A+%22test%40test.com%22%0APhone%3A+%22123-456-7890%22%0AMessage%3A+%22This+is+a+test+message%21%22&Message.Subject.Data=Contact+form+submission&Destination.ToAddresses.member.1=DudeDudely%40hotmail.com&Source=no_reply_contact_form_submission%40ThatBigTLD.com Fri Dec 02 20:19:12 UTC 2022 : Sending request to https://email.us-east-1.amazonaws.com/SendEmailToWhomeverILike Fri Dec 02 20:19:12 UTC 2022 : Received response. Status: 403, Integration latency: 21 ms Fri Dec 02 20:19:12 UTC 2022 : Endpoint response headers: {Date=Fri, 02 Dec 2022 20:19:12 GMT, Content-Type=application/json, Content-Length=300, Connection=keep-alive, x-amzn-RequestId=1559f1b5-7000-4fe5-9d70-38b729adba46} Fri Dec 02 20:19:12 UTC 2022 : Endpoint response body before transformations: {"Error":{"Code":"SignatureDoesNotMatch","Message":"The request signature we calculated does not match the signature you provided. Check your AWS Secret Access Key and signing method. Consult the service documentation for details.","Type":"Sender"},"RequestId":"1559f1b5-7000-4fe5-9d70-38b729adba46"} Fri Dec 02 20:19:12 UTC 2022 : Method response body after transformations: {"Error":{"Code":"SignatureDoesNotMatch","Message":"The request signature we calculated does not match the signature you provided. Check your AWS Secret Access Key and signing method. Consult the service documentation for details.","Type":"Sender"},"RequestId":"1559f1b5-7000-4fe5-9d70-38b729adba46"} Fri Dec 02 20:19:12 UTC 2022 : Method response headers: {X-Amzn-Trace-Id=Root=1-638a5dc0-85f935e6291eab49e7dbe023, Content-Type=application/json} Fri Dec 02 20:19:12 UTC 2022 : Successfully completed execution Fri Dec 02 20:19:12 UTC 2022 : Method completed with status: 200
测试用JSON负载
{ "name": "Test Name", "email": "test@test.com", "phone": "123-456-7890", "message": "This is a test message!" }
关联的IAM角色策略
{ "Version": "2012-10-17", "Statement": [ { "Sid": "Custom", "Effect": "Allow", "Action": [ "ses:SendEmail" ], "Resource": "*" } ] }
集成请求引用的IAM角色ARN
Execution role arn:aws:iam::<ABigNumberImNotGoingToShowYou>:role/ApiGatewaySes
核心问题
是否还需要发送其他类型的认证令牌?如果需要,应在何处配置相关信息?
解决方案
不需要额外发送认证令牌,API Gateway已通过指定的IAM角色完成请求签名。错误根源在于集成请求的端点URI配置错误,具体排查和修复步骤如下:
修正SES端点URI
从执行日志可以看到:- 计算签名用的URI是
https://email.us-east-1.amazonaws.com/SendEmail - 实际发送请求的地址是
https://email.us-east-1.amazonaws.com/SendEmailToWhomeverILike
SES不存在SendEmailToWhomeverILike这个API端点,导致签名验证失败。
修复:在API Gateway的集成请求中,将端点URI改为https://email.us-east-1.amazonaws.com,并通过映射模板在请求体中传递Action=SendEmail参数(而非拼在URI里)。
- 计算签名用的URI是
验证IAM角色的信任策略
确保你创建的ApiGatewaySes角色信任API Gateway服务,允许其扮演该角色。信任策略应包含:{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "Service": "apigateway.amazonaws.com" }, "Action": "sts:AssumeRole" } ] }检查映射模板的正确性
确认集成请求的映射模板正确将JSON负载转换为SES要求的表单格式,确保Action参数值为SendEmail,且所有参数编码正确。后续验证(非当前错误直接原因)
修复签名问题后,需确保SES的发件邮箱已完成验证,避免后续出现发送权限问题。
内容的提问来源于stack exchange,提问作者James Eastman
相关产品推荐
相关产品推荐

