aws / aws/serverless-java-container
API Gateway MTLS "clientCert" Availability?
- Dominant language
- Java
- Stars
- 1.6k
- Forks
- 574
- PR merge metrics
- No merged PRs in 30d
Description
*Serverless Java Container version*: `eg. 1.5`
1.6
*Implementations:* `Jersey / Spring / Spring Boot / Spring Boot 2 / Spark`
Spring Boot
*Framework version:* `eg SpringBoot 2.2.6.RELEASE`
2.6.6
*Frontend service:* `REST API / HTTP API / ALB`
REST API
## Scenario
I am utilizing MTLS authentication for my API Gateway: https://aws.amazon.com/blogs/compute/introducing-mutual-tls-authentication-for-amazon-api-gateway/
In the documentation, it mentions that the `clientCert` is populated in the API GW's event payload when it is passed along to Lambda authorizers via the `requestContext`.
I want to base my authorization on the clientCert's subjectDN's CN within my java code, but I am not sure if it's possible or how I can access the `clientCert` from within my Java lambda utilizing aws-serverless-java-container. (I realize the lambda isn't a `lambda authorizer`, but I was hoping it may still be accessible) Any suggestions?
## Expected behavior
I would expect that `clientCert` is available within `AwsProxyRequest`'s `AwsProxyRequestContext`
EX:
```"requestContext": {
"authentication": {
"clientCert": {
"clientCertPem": "-----BEGIN CERTIFICATE-----\nMIIEZTCCAk0CAQEwDQ...",
"issuerDN": "C=US,ST=Washington,L=Seattle,O=Amazon Web Services,OU=Security,CN=My Private CA",
"serialNumber": "1",
"subjectDN": "C=US,ST=Washington,L=Seattle,O=Amazon Web Services,OU=Security,CN=My Client",
"validity": {
"notAfter": "Aug 5 00:28:21 2120 GMT",
"notBefore": "Aug 29 00:28:21 2020 GMT"
}
}
},
...
```
## Actual behavior
I don't see anything in `AwsProxyRequest` or `AwsProxyRequestContext` related to certs or authentication.
## Steps to reproduce
Set up a REST API Gateway pointing to your `aws-serverless-java-container` lambda. Add custom domain. Create certs. Enable MTLS. Make call to the REST API Gateway and attempt to find `clientCert` object from API GW event payload.
## Full log output
N/A
Contributor guide
Research direction
Start by inspecting AwsProxyRequest and AwsProxyRequestContext, then compare their available fields with the API Gateway event payload shown in the issue. Verify the REST API Gateway MTLS request path and determine whether the clientCert data reaches the Java container. Done means the supported request context exposes the certificate information or clearly documents that it is unavailable.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, java
- Domain
- api
- Issue type
- Feature
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100