Serverless Backend with AWS Lambda & API Gateway · Ders

API Gateway Yetkilendiricileri

Sağlam kimlik doğrulama için Lambda özel yetkilendiricileri ve JWT yetkilendiricileri dâhil çeşitli API Gateway yetkilendiricileri uygulayın.

2. ders / 411 adım

API Gateway Yetkilendiricileri, CoddyKit'te ücretsiz bir Serverless Backend with AWS Lambda & API Gateway dersidir. Bu, 4 dersinin 2. dersidir. Aşağıdan dersin tamamını ücretsiz okuyabilir, sonra tarayıcıda yerleşik kod editörü ve 7/24 yapay zeka koçu ile uygulamalı olarak pratik yapabilirsin. Bu, Serverless Backend with AWS Lambda & API Gateway öğrenme yolunun bir parçasıdır ve ilerlemeniz web ve CoddyKit uygulaması arasında senkronize olur. Serverless Backend with AWS Lambda & API Gateway kursu toplamda 4 dersten oluşur.

Bu dersin bazı bölümleri henüz çevrilmemiş olup İngilizce olarak gösterilmektedir.

API Gateway Authorizers Intro

Welcome! In this lesson, we'll learn how to secure your serverless APIs using API Gateway Authorizers. These are crucial for controlling who can access your backend services.

Think of an authorizer as a security guard at the entrance of your API. Before any request reaches your Lambda function or other backend service, the authorizer checks the request's credentials.

Why Use API Gateway Authorizers?

Authorizers provide robust authentication and authorization for your APIs. Here's why they are essential:

  • Protect Backend Resources: Prevent unauthorized access to your Lambda functions and other services.
  • Decouple Auth Logic: Separate authentication logic from your main business logic, keeping your functions cleaner.
  • Fine-Grained Access: Control access to specific API methods or resources based on user identity or roles.

Types of Authorizers

API Gateway offers several types of authorizers. Today, we'll focus on the two most flexible and commonly used:

  • Lambda Custom Authorizers: A Lambda function you write to perform custom authentication.
  • JWT Authorizers: API Gateway's native support for validating JSON Web Tokens (JWTs).

There's also IAM Authorizers, which use AWS IAM roles and policies, but we'll focus on the custom and JWT types here.

Lambda Custom Authorizers Explained

A Lambda Custom Authorizer is a Lambda function that you provide. API Gateway invokes this function with the incoming request's authorization token (e.g., from the Authorization header).

Your Lambda function then processes this token, performs its custom authentication logic (e.g., checks a database, calls an identity provider), and returns an IAM policy.

The Authorization Policy

The core output of your Lambda authorizer is an IAM policy document. This policy tells API Gateway whether to Allow or Deny the request to the target API endpoint.

It includes a principalId (the authenticated user's identifier) and a policyDocument specifying the permissions. If Allow, the request proceeds; if Deny, it's rejected with a 401 Unauthorized error.

Lambda Authorizer Code Example

Here's a simple Python Lambda function acting as an authorizer. It checks for a specific token and returns an 'Allow' or 'Deny' policy based on it.

Try changing the token in the test event to see different outputs!

def lambda_handler(event, context):
    token = event.get('authorizationToken')
    method_arn = event.get('methodArn')

    if token == "my-secret-token-123":
        # Allow access
        return {
            "principalId": "user123",
            "policyDocument": {
                "Version": "2012-10-17",
                "Statement": [
                    {
                        "Action": "execute-api:Invoke",
                        "Effect": "Allow",
                        "Resource": method_arn
                    }
                ]
            }
        }
    else:
        # Deny access
        return {
            "principalId": "anonymous",
            "policyDocument": {
                "Version": "2012-10-17",
                "Statement": [
                    {
                        "Action": "execute-api:Invoke",
                        "Effect": "Deny",
                        "Resource": method_arn
                    }
                ]
            }
        }

# --- Local Test (for demonstration) ---
if __name__ == "__main__":
    print("Testing with 'my-secret-token-123':")
    event_allow = {
        "authorizationToken": "my-secret-token-123",
        "methodArn": "arn:aws:execute-api:us-east-1:123456789012:/test/GET/items"
    }
    print(lambda_handler(event_allow, None))

    print("\nTesting with 'invalid-token':")
    event_deny = {
        "authorizationToken": "invalid-token",
        "methodArn": "arn:aws:execute-api:us-east-1:123456789012:/test/GET/items"
    }
    print(lambda_handler(event_deny, None))

JWT Authorizers Explained

JWT (JSON Web Token) Authorizers allow API Gateway to natively validate JWTs. Instead of writing a Lambda function, you configure API Gateway with details about your JWT issuer.

When a request with a JWT comes in, API Gateway automatically performs validation steps like:

  • Signature verification
  • Expiration checks
  • Audience and issuer validation

Configuring a JWT Authorizer

To set up a JWT authorizer, you typically provide API Gateway with:

  • Issuer URL: The URL of the identity provider (e.g., https://cognito-idp.us-east-1.amazonaws.com/us-east-1_XXXXXXX for Cognito).
  • Audience(s): A list of valid audiences for the token, ensuring the token is intended for your API.
  • Identity Source: The header where the JWT is expected (e.g., $request.header.Authorization).

API Gateway then uses these details to fetch public keys and validate incoming JWTs.

When to Use Which Authorizer?

Choosing between Lambda and JWT authorizers depends on your needs:

  • Lambda Authorizer: Use for highly custom authentication logic, integration with legacy systems, or identity providers not supporting standard OIDC/OAuth2. Offers maximum flexibility.
  • JWT Authorizer: Ideal when using standard identity providers like AWS Cognito User Pools, Auth0, Okta, etc. It's simpler to set up and has less operational overhead.

For most modern applications using standard identity providers, JWT authorizers are often the preferred choice.

Authorizer Quick Check

Time for a quick check on what you've learned about API Gateway Authorizers!

Recap: Securing with Authorizers

You've now learned about API Gateway Authorizers, a vital component for securing your serverless APIs!

  • Authorizers act as a front-door security check for your API endpoints.
  • Lambda Custom Authorizers offer maximum flexibility for custom authentication logic.
  • JWT Authorizers provide native, easy-to-configure validation for standard JSON Web Tokens.

By implementing authorizers, you ensure only legitimate requests access your backend services, enhancing the security of your applications.

Başlamak ücretsiz

Yapay zeka eğitmeniyle Serverless Backend with AWS Lambda & API Gateway öğren — ücretsiz

Tarayıcında gerçek kod yaz ve çalıştır, 7/24 yapay zeka eğitmeninden anında yardım al; web'de ya da uygulamada kaldığın yerden devam et.

Kurslar
12
Dersler
48

Sıkça Sorulan Sorular

“API Gateway Yetkilendiricileri” dersi ücretsiz mi?

Evet — “API Gateway Yetkilendiricileri” dersin tüm metni burada web'de ücretsiz olarak okunabilir. Etkileşimli olarak pratik yapmak (yerleşik kod editörü ve 7/24 yapay zeka koçu) ve Serverless Backend with AWS Lambda & API Gateway kursunun geri kalanını açmak için CoddyKit PRO'ya yükselt. Serverless Backend with AWS Lambda & API Gateway kursu toplamda 4 dersten oluşur.

“API Gateway Yetkilendiricileri” dersinde ne öğreneceğim?

Sağlam kimlik doğrulama için Lambda özel yetkilendiricileri ve JWT yetkilendiricileri dâhil çeşitli API Gateway yetkilendiricileri uygulayın. Serverless Backend with AWS Lambda & API Gateway ile uygulamalı kodu tarayıcıda doğrudan çalıştırarak pratik yaparsın ve 7/24 yapay zeka koçu dersi çalışırken sorularını yanıtlar.

Serverless Backend with AWS Lambda & API Gateway öğrenmeye başlamak için deneyim gerekli mi?

Önceden deneyim gerekmez. CoddyKit'te Serverless Backend with AWS Lambda & API Gateway, başlangıçtan ileri seviyeye kadar yapılandırıldığı için buradan başlayabilir veya başından başlayıp kendi hızında ilerleme yapabilirsin. Bu, 4 dersinin 2. dersidir.

“API Gateway Yetkilendiricileri” dersi ne kadar sürer?

Çoğu CoddyKit dersi yaklaşık 5–10 dakika sürer. Her biri kısa ve etkileşimli olduğu için sabit ilerleme yaparsın ve web ile uygulama arasında tam olarak bıraktığın yerden devam edebilirsin.

Bu Serverless Backend with AWS Lambda & API Gateway dersinde kod yazıp çalıştırabilir miyim?

Evet. Her Serverless Backend with AWS Lambda & API Gateway dersi yerleşik bir kod editörü içerir, bu sayede tarayıcıda gerçek kod yazıp çalıştırabilir ve anlık yapay zeka geri bildirimi alırsın — yerel kurulum gerekli değildir.

Bu kursun tüm dersleri

  1. IAM Rolleri ve İzinleri
  2. API Gateway Yetkilendiricileri
  3. VPC ile Lambda'yı Güvenli Hale Getirme
  4. AWS Secrets Manager ile Gizli Bilgileri Koruma
← Serverless Backend with AWS Lambda & API Gateway Sayfasına Dön