base2Services / base2Services/aws-lambda-http-check

Allow reading payload parameters from secret / parameter store

Open
#5 0 comments 0 reactions 0 assignees View on GitHub
enhancement lambda-http-check
Dominant language
Python
Stars
33
Forks
16
PR merge metrics
No merged PRs in 30d

Description

In case of authorization headers needing to be sent to HTTP(s) endpoint - they should be stored in secret store, rather than passed unencrypted as payload to lambda function. Suggestion is that if any value in payload is in following forms
- `aws:smps("path")`
- `aws:sm("store.key")`

They should be replaced with actual secret value from AWS System Manager Parameter Store (first form), or AWS Secrets Manager (2nd form).

Contributor guide

No contributing guide indexed for this repository

Research direction

No files or tests are named in the issue. Start by locating the Lambda payload handling and AWS configuration, then trace how values are sent to the HTTP endpoint. Done means payload values using both specified forms are resolved from the corresponding AWS store before the request is made, without exposing the secrets in the payload.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, python
Domain
cloud, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.