Is there any way to create custom aws lambda authorizer using Spring Boot Function?

Viewed 172

I am trying to create a custom API Gateway lambda authorizer using Spring Cloud Function. But when I am trying to return policy document as Map<String,Object> from Spring Function, Spring returning it as body along with some extra metadata. So ApiGateway treating it as invalid json. How to return only policy document.

This is what the String Function returning when I return Map<String,Object>. My Map Object data is in body.

{


"isBase64Encoded":false,
   "headers":{
      "id":"6b9da9d5-23a7-b555-aecf-90e6134779b8",
      "contentType":"application/json",
      "timestamp":"1630300611676"
   },
   "body":"{\"policyDocument\":{\"Version\":\"2012-10-17\",\"Statement\":[{\"Action\":\"execute-api:Invoke\",\"Resource\":\"arn-value\",\"Effect\":\"Allow\"}]},\"context\":{\"name\":\"test\"},\"principalId\":\"813bf219-6039-4065-bcce-3e03b6996872\"}",
   "statusCode":200
}

But it should actually return only body part for ApiGateway to work correctly.

    {
   "policyDocument":{
      "Version":"2012-10-17",
      "Statement":[
         {
            "Action":"execute-api:Invoke",
            "Resource":"arn-value",
            "Effect":"Allow"
         }
      ]
   },
   "context":{
      "name":"test"
   },
   "principalId":"813bf219-6039-4065-bcce-3e03b6996872"
}

My Spring Cloud Function code is below. It is only test function without proper logic.

@Bean
    public Function<APIGatewayProxyRequestEvent, Map<String,Object>> authorise() {
        return request -> {
            String token = request.getHeaders().get("Authorization");
            String arn =  String.format("arn:aws:execute-api:%s:%s:%s/%s/%s/",
                    System.getenv("AWS_REGION"),
                    request.getRequestContext().getAccountId(),
                    request.getRequestContext().getApiId(),
                    request.getRequestContext().getStage(),
                    request.getRequestContext().getHttpMethod());
              //  Policy policy = jwtToken.getPolicy(token, arn);
            try{
                
                String allow = request.getHttpMethod().equalsIgnoreCase("GET")?"Allow":"Deny";
                JSONObject json = new JSONObject();
                json.put("principalId", UUID.randomUUID().toString())
                .put("policyDocument",
                        new JSONObject()
                                .put("Version", "2012-10-17")
                                .put("Statement",
                                        new JSONArray()
                                                .put(new JSONObject()
                                                        .put("Action", "execute-api:Invoke")
                                                        .put("Effect", allow)
                                                        .put("Resource", arn)
                                                )
                                )
                )
                .put("context", new JSONObject().put("name", "test"));
                return json.toMap();
            }catch(Exception e){
                logger.error("",e); 
            }
            return null;
        };
    }
0 Answers
Related