1 個回答
- 最新
- 最多得票
- 最多評論
0
According to the documentation you are correct. Only the headers/parameters are passed into the Authorizer which would make sense as during a POST you wouldn’t be sending a body as such and would only be interested in variables.
You would usually pass through a bearer token as such which would check to see if you have valid credentials and allow or deny you. You still need another authentication process to obtain a token to supply to api gateway.
https://docs.aws.amazon.com/apigateway/latest/developerguide/http-api-lambda-authorizer.html
相關內容
- AWS 官方已更新 2 年前