【问题标题】:Set AWS Authorizer entry for ASP.NET Core lambda function serverless.template file为 ASP.NET Core lambda 函数 serverless.template 文件设置 AWS Authorizer 条目
【发布时间】:2019-03-30 19:54:39
【问题描述】:

我正在尝试在我的 .Net Core Web API 应用上设置一个已经存在的授权函数。 当我使用纯 aws lambda nodejs 时,.yml 文件来完成它,看起来像这样:

custom:
  defaultStage: test
  currentStage: ${opt:stage, self:custom.defaultStage} 
  defaultRegion: us-east-1
  currentRegion: ${opt:region, self:custom.defaultRegion}
  **defaultAuthorizer**: us-east-1:xxxxxxxx:function:TypeToken-test-Authorizer
  **currentAuthorizer**: ${opt:authorizer, self:custom.defaultAuthorizer}

provider:
  name: aws
  runtime: nodejs6.10
  stage: ${self:custom.currentStage}
  profile: ${opt:profile, "default"} 
  region: ${self:custom.currentRegion}

functions:
  MyFunctionName:
    handler: handlerTestAPI.myFunctionName
    events:
      - http:
          path: myFunctionName
          method: post
          cors: true
          integration: lambda
          **authorizer:**
            arn: arn:aws:lambda:${self:custom.currentAuthorizer}
            resultTtlInSeconds: 0
            identitySource: method.request.header.Authorization
            type: token

对于这种情况,ASP.NET Core App serverless.template 文件类似于:

"Resources" : {

    "AspNetCoreFunction" : {
      "Type" : "AWS::Serverless::Function",
      "Properties": {
        "Handler": "Test.API::Project.API.LambdaEntryPoint::FunctionHandlerAsync",
        "Runtime": "dotnetcore2.1",
        "CodeUri": "",
        "MemorySize": 256,
        "Timeout": 30,
        "Role": null,
        "Policies": [ "AWSLambdaFullAccess" ],
        "Environment" : {
          "Variables" : {
            "TestTable" : { "Fn::If" : ["CreateProjectTable", {"Ref":"ProjectTable"}, { "Ref" : "ProjectTableName" } ] }
          }
        },
        "Events": {
          "PutResource": {
            "Type": "Api",
            "Properties": {
              "Path": "/{proxy+}",
              "Method": "ANY"
            }
          }
        }
      }
    }

我已经搜索了使用 serverless.template 文件在 .net 核心无服务器功能之上设置现有授权方的模板,但还没有找到。

感谢您的反馈。

【问题讨论】:

    标签: .net amazon-web-services asp.net-core aws-lambda asp.net-core-webapi


    【解决方案1】:

    我认为这是一个被广泛要求的功能,但在until a few days 之前尚不支持

    github页面现已更新

    https://github.com/awslabs/serverless-application-model/blob/master/versions/2016-10-31.md#api

    现在您可以使用 AUTH 属性

    Auth configuration for this specific Api+Path+Method. Useful for overriding the API's DefaultAuthorizer or setting auth config on an individual path when no DefaultAuthorizer is specified.
    

    默认模板生成隐式 API 网关。要设置anthorizer,您可能需要create an explicit API gateway

    另外,他们的 Github 页面上有一个example

    【讨论】:

    • 几天前我也看到了这个选项,并尝试了类似的东西:“Events”:{“PutResource”:{“Type”:“Api”,“Properties”:{“Path”:“/ {proxy+}", "Method": "ANY", "Auth": { "DefaultAuthorizer": "MyAuthorizer", "Authorizers": { "MyAuthorizer": { "FunctionPayloadType": "TOKEN", "FunctionArn": "arn :aws:lambda:us-west-1:1234343545:function:MyAuthorizer-env-Lambda" } } } } } 但在使用更新了无服务器文件。
    • @CoderRoller 你能去你的控制台 => CloudFormation => 你的 API => [在设计器中编辑模板] 看看生成的 JSON 是否有任何变化?
    • 我在原始模板中看到:Events":{"PutResource":{"Type":"Api","Properties":{"Path":"/{proxy+}"," Method":"ANY","Auth":{"DefaultAuthorizer":"MyAuthorizer"}},但我在处理的模板中看不到它。我已经安装了最新版本的 .NetCore SDK 和适用于 Visual Studio 2017 的 AWS 工具 btw .
    • @CoderRoller 我刚刚检查了最新版本。默认模板生成隐式 API 网关。要设置 anthorizer,我需要创建一个显式 API 网关。这应该让你更容易理解imgur.com/OkM9vpo和GitHub示例页面github.com/awslabs/serverless-application-model/blob/release/…
    • 我在这里尝试了配置:imgur.com/EYwgRcs,但是让我完成了回滚,当我看到事件日志时,我看到了这个:imgur.com/a/1qZvkWo,请注意我只是使用了一个已经部署的授权器,并且它的 ARN,所以我没有你的图像中的 MyAuthFunction 部分。我也需要那个吗?还是现在只能是权限问题?非常感谢。
    猜你喜欢
    • 1970-01-01
    • 2020-11-07
    • 2018-08-08
    • 2022-12-28
    • 1970-01-01
    • 2019-07-21
    • 2020-03-17
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多