Implementing SAML-Based Login and API Authorization with API Gateway, Lambda Authorizer, and Microsoft IDP

1

I'm currently working on implementing SAML-based login and API request authorization using AWS API Gateway, Lambda Authorizer, and a Microsoft Identity Provider (IDP). The architecture I'm following involves several steps (refer image below), and I'm seeking clarification on two specific points:

1. Receiving the SAML Token on My Page (Step 3): I'm unclear about how my web page should receive the SAML token. What is the recommended approach for obtaining the SAML token after a successful login? Are there specific API endpoints or protocols involved in this step?

2. Lambda Authorizing the Token with the IDP (Step 6): I'm also seeking guidance on how the Lambda Authorizer should handle the authorization process with the Microsoft IDP. What steps should the Lambda function take to validate and authorize the received SAML token against the IDP?

Any insights, code snippets, or references to relevant documentation would be greatly appreciated. I'm looking forward to a clearer understanding of these specific steps in the SAML-based login and authorization process.

 architecture

1 réponse
0
Réponse acceptée

You could look at following articles: https://repost.aws/knowledge-center/cognito-third-party-saml-idp which rely on cognito

profile picture
EXPERT
répondu il y a 5 mois
profile picture
EXPERT
vérifié il y a 2 mois
  • Thanks for the suggestion! I appreciate your input and will definitely check it out.

Vous n'êtes pas connecté. Se connecter pour publier une réponse.

Une bonne réponse répond clairement à la question, contient des commentaires constructifs et encourage le développement professionnel de la personne qui pose la question.

Instructions pour répondre aux questions