Cloudfront does not forward the Referer Header

Viewed 324

I would like Cloudfront to forward the Referer header to my origin, but I can't do it. First I have created Cache Policy and configured to forward the Referer Header, then I also created Request Origin Policy with the same setting just to get it working

Here is my code:

CloudfrontCachePolicy:
      Type: AWS::CloudFront::CachePolicy
      Properties:
        CachePolicyConfig:
          Name: cache-policy
          Comment: Cache Optimized Policy (forward  referer and query string)
          DefaultTTL: 86400
          MaxTTL: 31536000
          MinTTL: 1
          ParametersInCacheKeyAndForwardedToOrigin:
            EnableAcceptEncodingBrotli: true
            EnableAcceptEncodingGzip: true
            CookiesConfig:
              CookieBehavior: none
            HeadersConfig:
              HeaderBehavior: whitelist
              Headers:
                - Referer
            QueryStringsConfig:
              QueryStringBehavior: all



CloudfronOriginRequestPolicy:
      Type: AWS::CloudFront::OriginRequestPolicy
      Properties:
        OriginRequestPolicyConfig:
          Name: origin-request-policy
          Comment: Origin Request Policy (forward referer  query string)
          CookiesConfig:
            CookieBehavior: none
          HeadersConfig:
            HeaderBehavior: whitelist
            Headers:
              - Referer
          QueryStringsConfig:
            QueryStringBehavior: all




 CloudfrontDistribution:
      Type: AWS::CloudFront::Distribution
      DependsOn: [FrontendBucket]
      Properties:
        DistributionConfig:
          Enabled: true
          Comment: "(${self:provider.stage}-${opt:lang})"
          Aliases: ${self:custom.domainCondition.${self:provider.stage}.${opt:lang}, self:custom.domainCondition.other}
          ViewerCertificate:
            AcmCertificateArn: "${self:custom.certificateCondition.${self:provider.stage}.${opt:lang}, self:custom.certificateCondition.other.${opt:lang}}"
            MinimumProtocolVersion: TLSv1.2_2018
            SslSupportMethod: sni-only
          Origins:
            - Id:
                Ref: FrontendBucket
              DomainName: "${self:custom.frontendBucketName}.s3-website-${self:provider.region}.amazonaws.com"
              CustomOriginConfig:
                OriginProtocolPolicy: http-only
                HTTPPort: 80
                HTTPSPort: 443
          DefaultCacheBehavior:
            TargetOriginId:
              Ref: FrontendBucket
            ViewerProtocolPolicy: redirect-to-https
            Compress: true
            CachePolicyId:
              Ref: CloudfrontCachePolicy
            OriginRequestPolicyId:
              Ref: CloudfronOriginRequestPolicy
            AllowedMethods:
              - GET
              - HEAD
              - OPTIONS
            CachedMethods:
              - GET
              - HEAD
            LambdaFunctionAssociations:
              - EventType: "origin-request"
                LambdaFunctionARN: ${cf.us-east-1:my-website-cle-${self:provider.stage}.RequestCLELambdaFunctionQualifiedArn}
              - EventType: "origin-response"
                LambdaFunctionARN: ${cf.us-east-1:my-website-cle-${self:provider.stage}.ResponseCLELambdaFunctionQualifiedArn}

When I try to log the headers in Origin Request Lambda@Edge the referer is not showing.

It is interesting that if I add headers to forward Referer and Host. The Referer header is forwarded as well. But I do not want to forward the Host header since it is a S3 static website and the Host of that is different and it does not work.

Any suggestions ?

0 Answers
Related