How can I only allow a specific origin to access content from Cloudfront/S3 Origins when requested via iFrame?

Viewed 426

Here is an image of the general idea I want to accomplish

I have a react application that is hosted as a Zendesk app via an iFrame from subdomain.zendesk.com, the iFrame fetches the content from Cloudfront / S3 (using S3 Origins) and displays it within the Zendesk UI.

I'm trying to secure it and want to restrict access to the content to a specific origin (subdomain.zendesk.com for example) so that if anyone was to view the Cloudfront distribution directly (by navigating to xxxx.cloudfront.net) it would reject the request.

How can this be achieved? I have tried using AWS WAF and creating a rule that looks at the request origin header and matches it against the subdomain url (example origin: subdomain.zendesk.com) but that doesn't work so I think i'm barking up the wrong tree using that.

I have also tried creating a custom origin request policy on the distributions behaviour but again that didn't yield any results.

Zendesk does offer signed url functionality where the initial request becomes a POST request to the server that contains a JWT as form data in the request payload, I read that it might be possible to use Lambda@edge to accomplish this, I tried to implement this but I have not had any luck so far.

Any tips, examples or outlines as to what I am misunderstanding about these services would be very much appreciated.

1 Answers

In order to get a better support from the community, share the specific use-cases in your question and share in detail what you tried and what are the errors.

There are various ways to achieve what you mentioned in the picture:

  • Create multiple CloudFront Distributions for each domain and they can have either same or unique origins as per the need

  • Instead of domain, redirect traffic using "paths" or "routes" for e.g.: same-domain.com/path1 same-domain.com/path2 etc

  • Use Lambda@Edge and redirect the traffic based on domains

you can't have redirection (Behaviours functionality of CloudFront) using multiple domains

Related