Documentation
¶
Index ¶
- func NewHttpIamAuthorizer_Override(h HttpIamAuthorizer)
- func NewHttpJwtAuthorizer_Override(h HttpJwtAuthorizer, id *string, jwtIssuer *string, ...)
- func NewHttpLambdaAuthorizer_Override(h HttpLambdaAuthorizer, id *string, handler awslambda.IFunction, ...)
- func NewHttpUserPoolAuthorizer_Override(h HttpUserPoolAuthorizer, id *string, pool awscognito.IUserPool, ...)
- func NewWebSocketLambdaAuthorizer_Override(w WebSocketLambdaAuthorizer, id *string, handler awslambda.IFunction, ...)
- type HttpIamAuthorizer
- type HttpJwtAuthorizer
- type HttpJwtAuthorizerProps
- type HttpLambdaAuthorizer
- type HttpLambdaAuthorizerProps
- type HttpLambdaResponseType
- type HttpUserPoolAuthorizer
- type HttpUserPoolAuthorizerProps
- type WebSocketLambdaAuthorizer
- type WebSocketLambdaAuthorizerProps
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func NewHttpIamAuthorizer_Override ¶
func NewHttpIamAuthorizer_Override(h HttpIamAuthorizer)
Experimental.
func NewHttpJwtAuthorizer_Override ¶
func NewHttpJwtAuthorizer_Override(h HttpJwtAuthorizer, id *string, jwtIssuer *string, props *HttpJwtAuthorizerProps)
Initialize a JWT authorizer to be bound with HTTP route. Experimental.
func NewHttpLambdaAuthorizer_Override ¶
func NewHttpLambdaAuthorizer_Override(h HttpLambdaAuthorizer, id *string, handler awslambda.IFunction, props *HttpLambdaAuthorizerProps)
Initialize a lambda authorizer to be bound with HTTP route. Experimental.
func NewHttpUserPoolAuthorizer_Override ¶
func NewHttpUserPoolAuthorizer_Override(h HttpUserPoolAuthorizer, id *string, pool awscognito.IUserPool, props *HttpUserPoolAuthorizerProps)
Initialize a Cognito user pool authorizer to be bound with HTTP route. Experimental.
func NewWebSocketLambdaAuthorizer_Override ¶
func NewWebSocketLambdaAuthorizer_Override(w WebSocketLambdaAuthorizer, id *string, handler awslambda.IFunction, props *WebSocketLambdaAuthorizerProps)
Experimental.
Types ¶
type HttpIamAuthorizer ¶
type HttpIamAuthorizer interface {
awsapigatewayv2.IHttpRouteAuthorizer
// Bind this authorizer to a specified Http route.
// Experimental.
Bind(_options *awsapigatewayv2.HttpRouteAuthorizerBindOptions) *awsapigatewayv2.HttpRouteAuthorizerConfig
}
Authorize HTTP API Routes with IAM.
Example:
import "github.com/aws/aws-cdk-go/awscdk"
import "github.com/aws/aws-cdk-go/awscdk"
var principal anyPrincipal
authorizer := awscdk.NewHttpIamAuthorizer()
httpApi := apigwv2.NewHttpApi(this, jsii.String("HttpApi"), &httpApiProps{
defaultAuthorizer: authorizer,
})
routes := httpApi.addRoutes(&addRoutesOptions{
integration: awscdk.NewHttpUrlIntegration(jsii.String("BooksIntegration"), jsii.String("https://get-books-proxy.myproxy.internal")),
path: jsii.String("/books/{book}"),
})
routes[0].grantInvoke(principal)
Experimental.
type HttpJwtAuthorizer ¶
type HttpJwtAuthorizer interface {
awsapigatewayv2.IHttpRouteAuthorizer
// Bind this authorizer to a specified Http route.
// Experimental.
Bind(options *awsapigatewayv2.HttpRouteAuthorizerBindOptions) *awsapigatewayv2.HttpRouteAuthorizerConfig
}
Authorize Http Api routes on whether the requester is registered as part of an AWS Cognito user pool.
Example:
import "github.com/aws/aws-cdk-go/awscdk"
import "github.com/aws/aws-cdk-go/awscdk"
issuer := "https://test.us.auth0.com"
authorizer := awscdk.NewHttpJwtAuthorizer(jsii.String("BooksAuthorizer"), issuer, &httpJwtAuthorizerProps{
jwtAudience: []*string{
jsii.String("3131231"),
},
})
api := apigwv2.NewHttpApi(this, jsii.String("HttpApi"))
api.addRoutes(&addRoutesOptions{
integration: awscdk.NewHttpUrlIntegration(jsii.String("BooksIntegration"), jsii.String("https://get-books-proxy.myproxy.internal")),
path: jsii.String("/books"),
authorizer: authorizer,
})
Experimental.
func NewHttpJwtAuthorizer ¶
func NewHttpJwtAuthorizer(id *string, jwtIssuer *string, props *HttpJwtAuthorizerProps) HttpJwtAuthorizer
Initialize a JWT authorizer to be bound with HTTP route. Experimental.
type HttpJwtAuthorizerProps ¶
type HttpJwtAuthorizerProps struct {
// A list of the intended recipients of the JWT.
//
// A valid JWT must provide an aud that matches at least one entry in this list.
// Experimental.
JwtAudience *[]*string `field:"required" json:"jwtAudience" yaml:"jwtAudience"`
// The name of the authorizer.
// Experimental.
AuthorizerName *string `field:"optional" json:"authorizerName" yaml:"authorizerName"`
// The identity source for which authorization is requested.
// Experimental.
IdentitySource *[]*string `field:"optional" json:"identitySource" yaml:"identitySource"`
}
Properties to initialize HttpJwtAuthorizer.
Example:
import "github.com/aws/aws-cdk-go/awscdk"
import "github.com/aws/aws-cdk-go/awscdk"
issuer := "https://test.us.auth0.com"
authorizer := awscdk.NewHttpJwtAuthorizer(jsii.String("BooksAuthorizer"), issuer, &httpJwtAuthorizerProps{
jwtAudience: []*string{
jsii.String("3131231"),
},
})
api := apigwv2.NewHttpApi(this, jsii.String("HttpApi"))
api.addRoutes(&addRoutesOptions{
integration: awscdk.NewHttpUrlIntegration(jsii.String("BooksIntegration"), jsii.String("https://get-books-proxy.myproxy.internal")),
path: jsii.String("/books"),
authorizer: authorizer,
})
Experimental.
type HttpLambdaAuthorizer ¶
type HttpLambdaAuthorizer interface {
awsapigatewayv2.IHttpRouteAuthorizer
// Bind this authorizer to a specified Http route.
// Experimental.
Bind(options *awsapigatewayv2.HttpRouteAuthorizerBindOptions) *awsapigatewayv2.HttpRouteAuthorizerConfig
}
Authorize Http Api routes via a lambda function.
Example:
import "github.com/aws/aws-cdk-go/awscdk"
import "github.com/aws/aws-cdk-go/awscdk"
// This function handles your auth logic
var authHandler function
authorizer := awscdk.NewHttpLambdaAuthorizer(jsii.String("BooksAuthorizer"), authHandler, &httpLambdaAuthorizerProps{
responseTypes: []httpLambdaResponseType{
awscdk.HttpLambdaResponseType_SIMPLE,
},
})
api := apigwv2.NewHttpApi(this, jsii.String("HttpApi"))
api.addRoutes(&addRoutesOptions{
integration: awscdk.NewHttpUrlIntegration(jsii.String("BooksIntegration"), jsii.String("https://get-books-proxy.myproxy.internal")),
path: jsii.String("/books"),
authorizer: authorizer,
})
Experimental.
func NewHttpLambdaAuthorizer ¶
func NewHttpLambdaAuthorizer(id *string, handler awslambda.IFunction, props *HttpLambdaAuthorizerProps) HttpLambdaAuthorizer
Initialize a lambda authorizer to be bound with HTTP route. Experimental.
type HttpLambdaAuthorizerProps ¶
type HttpLambdaAuthorizerProps struct {
// Friendly authorizer name.
// Experimental.
AuthorizerName *string `field:"optional" json:"authorizerName" yaml:"authorizerName"`
// The identity source for which authorization is requested.
// Experimental.
IdentitySource *[]*string `field:"optional" json:"identitySource" yaml:"identitySource"`
// The types of responses the lambda can return.
//
// If HttpLambdaResponseType.SIMPLE is included then
// response format 2.0 will be used.
// See: https://docs.aws.amazon.com/apigateway/latest/developerguide/http-api-lambda-authorizer.html#http-api-lambda-authorizer.payload-format-response
//
// Experimental.
ResponseTypes *[]HttpLambdaResponseType `field:"optional" json:"responseTypes" yaml:"responseTypes"`
// How long APIGateway should cache the results.
//
// Max 1 hour.
// Disable caching by setting this to `Duration.seconds(0)`.
// Experimental.
ResultsCacheTtl awscdk.Duration `field:"optional" json:"resultsCacheTtl" yaml:"resultsCacheTtl"`
}
Properties to initialize HttpTokenAuthorizer.
Example:
import "github.com/aws/aws-cdk-go/awscdk"
import "github.com/aws/aws-cdk-go/awscdk"
// This function handles your auth logic
var authHandler function
authorizer := awscdk.NewHttpLambdaAuthorizer(jsii.String("BooksAuthorizer"), authHandler, &httpLambdaAuthorizerProps{
responseTypes: []httpLambdaResponseType{
awscdk.HttpLambdaResponseType_SIMPLE,
},
})
api := apigwv2.NewHttpApi(this, jsii.String("HttpApi"))
api.addRoutes(&addRoutesOptions{
integration: awscdk.NewHttpUrlIntegration(jsii.String("BooksIntegration"), jsii.String("https://get-books-proxy.myproxy.internal")),
path: jsii.String("/books"),
authorizer: authorizer,
})
Experimental.
type HttpLambdaResponseType ¶
type HttpLambdaResponseType string
Specifies the type responses the lambda returns. Experimental.
const ( // Returns simple boolean response. // Experimental. HttpLambdaResponseType_SIMPLE HttpLambdaResponseType = "SIMPLE" // Returns an IAM Policy. // Experimental. HttpLambdaResponseType_IAM HttpLambdaResponseType = "IAM" )
type HttpUserPoolAuthorizer ¶
type HttpUserPoolAuthorizer interface {
awsapigatewayv2.IHttpRouteAuthorizer
// Bind this authorizer to a specified Http route.
// Experimental.
Bind(options *awsapigatewayv2.HttpRouteAuthorizerBindOptions) *awsapigatewayv2.HttpRouteAuthorizerConfig
}
Authorize Http Api routes on whether the requester is registered as part of an AWS Cognito user pool.
Example:
import cognito "github.com/aws/aws-cdk-go/awscdk"
import "github.com/aws/aws-cdk-go/awscdk"
import "github.com/aws/aws-cdk-go/awscdk"
userPool := cognito.NewUserPool(this, jsii.String("UserPool"))
authorizer := awscdk.NewHttpUserPoolAuthorizer(jsii.String("BooksAuthorizer"), userPool)
api := apigwv2.NewHttpApi(this, jsii.String("HttpApi"))
api.addRoutes(&addRoutesOptions{
integration: awscdk.NewHttpUrlIntegration(jsii.String("BooksIntegration"), jsii.String("https://get-books-proxy.myproxy.internal")),
path: jsii.String("/books"),
authorizer: authorizer,
})
Experimental.
func NewHttpUserPoolAuthorizer ¶
func NewHttpUserPoolAuthorizer(id *string, pool awscognito.IUserPool, props *HttpUserPoolAuthorizerProps) HttpUserPoolAuthorizer
Initialize a Cognito user pool authorizer to be bound with HTTP route. Experimental.
type HttpUserPoolAuthorizerProps ¶
type HttpUserPoolAuthorizerProps struct {
// Friendly name of the authorizer.
// Experimental.
AuthorizerName *string `field:"optional" json:"authorizerName" yaml:"authorizerName"`
// The identity source for which authorization is requested.
// Experimental.
IdentitySource *[]*string `field:"optional" json:"identitySource" yaml:"identitySource"`
// The user pool clients that should be used to authorize requests with the user pool.
// Experimental.
UserPoolClients *[]awscognito.IUserPoolClient `field:"optional" json:"userPoolClients" yaml:"userPoolClients"`
// The AWS region in which the user pool is present.
// Experimental.
UserPoolRegion *string `field:"optional" json:"userPoolRegion" yaml:"userPoolRegion"`
}
Properties to initialize HttpUserPoolAuthorizer.
Example:
// The code below shows an example of how to instantiate this type.
// The values are placeholders you should change.
import "github.com/aws/aws-cdk-go/awscdk"
import "github.com/aws/aws-cdk-go/awscdk"
var userPoolClient userPoolClient
httpUserPoolAuthorizerProps := &httpUserPoolAuthorizerProps{
authorizerName: jsii.String("authorizerName"),
identitySource: []*string{
jsii.String("identitySource"),
},
userPoolClients: []iUserPoolClient{
userPoolClient,
},
userPoolRegion: jsii.String("userPoolRegion"),
}
Experimental.
type WebSocketLambdaAuthorizer ¶
type WebSocketLambdaAuthorizer interface {
awsapigatewayv2.IWebSocketRouteAuthorizer
// Bind this authorizer to a specified WebSocket route.
// Experimental.
Bind(options *awsapigatewayv2.WebSocketRouteAuthorizerBindOptions) *awsapigatewayv2.WebSocketRouteAuthorizerConfig
}
Authorize WebSocket Api routes via a lambda function.
Example:
import "github.com/aws/aws-cdk-go/awscdk"
import "github.com/aws/aws-cdk-go/awscdk"
// This function handles your auth logic
var authHandler function
// This function handles your WebSocket requests
var handler function
authorizer := awscdk.NewWebSocketLambdaAuthorizer(jsii.String("Authorizer"), authHandler)
integration := awscdk.NewWebSocketLambdaIntegration(jsii.String("Integration"), handler)
apigwv2.NewWebSocketApi(this, jsii.String("WebSocketApi"), &webSocketApiProps{
connectRouteOptions: &webSocketRouteOptions{
integration: integration,
authorizer: authorizer,
},
})
Experimental.
func NewWebSocketLambdaAuthorizer ¶
func NewWebSocketLambdaAuthorizer(id *string, handler awslambda.IFunction, props *WebSocketLambdaAuthorizerProps) WebSocketLambdaAuthorizer
Experimental.
type WebSocketLambdaAuthorizerProps ¶
type WebSocketLambdaAuthorizerProps struct {
// The name of the authorizer.
// Experimental.
AuthorizerName *string `field:"optional" json:"authorizerName" yaml:"authorizerName"`
// The identity source for which authorization is requested.
//
// Request parameter match `'route.request.querystring|header.[a-zA-z0-9._-]+'`.
// Staged variable match `'stageVariables.[a-zA-Z0-9._-]+'`.
// Context parameter match `'context.[a-zA-Z0-9._-]+'`.
// Experimental.
IdentitySource *[]*string `field:"optional" json:"identitySource" yaml:"identitySource"`
}
Properties to initialize WebSocketTokenAuthorizer.
Example:
// The code below shows an example of how to instantiate this type.
// The values are placeholders you should change.
import "github.com/aws/aws-cdk-go/awscdk"
webSocketLambdaAuthorizerProps := &webSocketLambdaAuthorizerProps{
authorizerName: jsii.String("authorizerName"),
identitySource: []*string{
jsii.String("identitySource"),
},
}
Experimental.