aws / aws/serverless-java-container
API Gateway MTLS "clientCert" Availability?
- Linguagem predominante
- Java
- Estrelas
- 1.6k
- Forks
- 574
- Métricas de merge de PRs
- Nenhum PR com merge em 30d
Descrição
*Serverless Java Container version*: `eg. 1.5`
1.6
*Implementations:* `Jersey / Spring / Spring Boot / Spring Boot 2 / Spark`
Spring Boot
*Framework version:* `eg SpringBoot 2.2.6.RELEASE`
2.6.6
*Frontend service:* `REST API / HTTP API / ALB`
REST API
## Scenario
I am utilizing MTLS authentication for my API Gateway: https://aws.amazon.com/blogs/compute/introducing-mutual-tls-authentication-for-amazon-api-gateway/
In the documentation, it mentions that the `clientCert` is populated in the API GW's event payload when it is passed along to Lambda authorizers via the `requestContext`.
I want to base my authorization on the clientCert's subjectDN's CN within my java code, but I am not sure if it's possible or how I can access the `clientCert` from within my Java lambda utilizing aws-serverless-java-container. (I realize the lambda isn't a `lambda authorizer`, but I was hoping it may still be accessible) Any suggestions?
## Expected behavior
I would expect that `clientCert` is available within `AwsProxyRequest`'s `AwsProxyRequestContext`
EX:
```"requestContext": {
"authentication": {
"clientCert": {
"clientCertPem": "-----BEGIN CERTIFICATE-----\nMIIEZTCCAk0CAQEwDQ...",
"issuerDN": "C=US,ST=Washington,L=Seattle,O=Amazon Web Services,OU=Security,CN=My Private CA",
"serialNumber": "1",
"subjectDN": "C=US,ST=Washington,L=Seattle,O=Amazon Web Services,OU=Security,CN=My Client",
"validity": {
"notAfter": "Aug 5 00:28:21 2120 GMT",
"notBefore": "Aug 29 00:28:21 2020 GMT"
}
}
},
...
```
## Actual behavior
I don't see anything in `AwsProxyRequest` or `AwsProxyRequestContext` related to certs or authentication.
## Steps to reproduce
Set up a REST API Gateway pointing to your `aws-serverless-java-container` lambda. Add custom domain. Create certs. Enable MTLS. Make call to the REST API Gateway and attempt to find `clientCert` object from API GW event payload.
## Full log output
N/A
Guia de contribuição
Direção de pesquisa
Comece inspecionando AwsProxyRequest e AwsProxyRequestContext e, em seguida, compare os campos disponíveis com o payload do evento do API Gateway mostrado na issue. Verifique o caminho da requisição MTLS do REST API Gateway e determine se os dados de clientCert chegam ao contêiner Java. Considera-se concluído quando o contexto de requisição compatível expõe as informações do certificado ou documenta claramente que elas não estão disponíveis.
Escrita pelo modelo de indexação a partir do texto da issue.
Avaliação
- Stack de tecnologia
- aws, java
- Domínio
- api
- Tipo de issue
- Funcionalidade
- Dificuldade
- 3/5
- Tempo estimado
- 1-2 dias
- Status de atividade
- Estagnada
- Clareza
- Razoavelmente clara
- Facilidade para iniciantes
- 35/100