Trusting Cognito accessToken in lambda (authorizer in use) - Authorization

Viewed 50

Is it safe for my lambda function to trust the accessToken passed by the user and checked by the lambda authorizer to perform CRUD db operations?

For example:

const authToken = event.headers['Authorization'];
if (!authToken) throw new Error('No auth token found so no username');
var decodedToken = jwt_decode(authToken);
const userName = decodedToken.username;    //---- BUT CAN WE TRUST THIS? ----
let params = {
  TableName: "myTable",
  IndexName: 'userName-gsi',
  KeyConditionExpression: 'userName = :userName',
  ExpressionAttributeValues: {
    ':userName': userName,
  },
  Limit: 1,
};
let data = await dynamodb.query(params).promise();
return {
  statusCode: 200,
  headers: utils.getResponseHeaderApplicantifyCors(),
  body: JSON.stringify(data.Items[0]),
};
1 Answers
Related