aws / aws/serverless-java-container

Unable to invoke lambda when "Authorization scopes" added to JWT Authorizer

オープン
#408 コメント 2 件 リアクション 0 件 担当者 0 名 GitHub で見る
need feedback
主要言語
Java
スター
1.6k
フォーク
574
PR マージ指標
30日以内にマージされた PR はありません

説明

*Serverless Java Container version*: `eg. 1.5.2`

*Implementations:* `Spring Boot 2`

*Framework version:* `eg SpringBoot 2.4.1`

*Frontend service:* `HTTP API`

*Deployment method:* `SAM`

## Scenario
*Describe what you are trying to accomplish*
I am trying to call invoke lambda via HTTP api with JWT authorizer. call to lambda are failing when i add "Authorization scopes" in the JWT authorizer(on HTTP api)

## Expected behavior
I would expect lambda should be able to be invoke with or without Authorization scopes in JWT authorizer

## Actual behavior
I am trying to call invoke lambda via HTTP api with JWT authorizer. call to lambda are failing when i add "Authorization scopes" in the JWT authorizer(on HTTP api) with error message

```com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot deserialize instance of `java.lang.String` out of START_ARRAY token
at [Source: (ByteArrayInputStream); line: 1, column: 3530] (through reference chain: com.amazonaws.serverless.proxy.model.AwsProxyRequest["requestContext"]->com.amazonaws.serverless.proxy.model.AwsProxyRequestContext["authorizer"]->com.amazonaws.serverless.proxy.model.ApiGatewayAuthorizerContext["scopes"])```

but without "Authorization scopes" in the JWT authorizer(on HTTP api) calls were going fine as long JWT is valid

## Steps to reproduce
Create a springboot 2 based AWS lambda with HTTP api and Authorization scope with scopes specified in it.

InputStream of call when Authorization scope is added contains a section with Scopes array but same is null when Authorization scope is not defined in JWT Authorizer in HTTP API

"scopes": [
"b",
"a",
"z",
"y",
"x"
]

InputStream of call when Authorization scope is not added

"scopes": null

## Full log output
*Paste the full log output from the Lambda function's CloudWatch logs*

```
logs
```

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

まず、SAM で Scopes を構成した HTTP API JWT authorizer の背後にある Spring Boot 2 AWS Lambda を再現します。例外で示されている AwsProxyRequest、AwsProxyRequestContext、ApiGatewayAuthorizerContext の場所を確認し、Scopes の値が配列の場合と null の場合の両方で invocation が成功することを検証します。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
aws, java, spring-boot
領域
api, authentication, cloud
issue の種類
バグ
難易度
3/5
見積もり時間
1〜2日
活発さ
停滞
明瞭さ
おおむね明確
初心者へのやさしさ
38/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。