I have backend services implemented in AWS Lambda (AWS::Serverless::Function + AWS::Serverless::RestAPI).
Originally I thought that I would use API Gateway to handle all CORS headers, so my Lambda is pure and agnostic to networking and Origin and traffic. When we integrated with our FE that is served from S3 via CloudFront, we encountered CORS problems and the only way we can find is to add following code into out Lambda handlers
resolve({
statusCode: 200,
headers: {
'Content-Type': 'application/json',
'Access-Control-Allow-Origin': '*'
},
body: JSON.stringify({
...accountDefinition,
}),
which explicitly couples our code with HTTP protocol and even deployment and Origin location.
Is there any way to configure this setup without forcing this code into our Lambda? I really hoped that AWS API GW is capable of shielding us from CORS and other stuff so we are not forced to couple our code with Origin and other stuff.
