Implementing SAML-Based Login and API Authorization with API Gateway, Lambda Authorizer, and Microsoft IDP

1

I'm currently working on implementing SAML-based login and API request authorization using AWS API Gateway, Lambda Authorizer, and a Microsoft Identity Provider (IDP). The architecture I'm following involves several steps (refer image below), and I'm seeking clarification on two specific points:

1. Receiving the SAML Token on My Page (Step 3): I'm unclear about how my web page should receive the SAML token. What is the recommended approach for obtaining the SAML token after a successful login? Are there specific API endpoints or protocols involved in this step?

2. Lambda Authorizing the Token with the IDP (Step 6): I'm also seeking guidance on how the Lambda Authorizer should handle the authorization process with the Microsoft IDP. What steps should the Lambda function take to validate and authorize the received SAML token against the IDP?

Any insights, code snippets, or references to relevant documentation would be greatly appreciated. I'm looking forward to a clearer understanding of these specific steps in the SAML-based login and authorization process.

 architecture

1 個回答
0
已接受的答案

You could look at following articles: https://repost.aws/knowledge-center/cognito-third-party-saml-idp which rely on cognito

profile picture
專家
已回答 5 個月前
profile picture
專家
已審閱 1 個月前
  • Thanks for the suggestion! I appreciate your input and will definitely check it out.

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。

回答問題指南