runway.blueprints.staticsite.auth_at_edge module

Blueprint for the Authorization@Edge implementation of a Static Site.

Described in detail in this blogpost: https://aws.amazon.com/blogs/networking-and-content-delivery/authorizationedge-how-to-use-lambdaedge-and-json-web-tokens-to-enhance-web-application-security/

class runway.blueprints.staticsite.auth_at_edge.AuthAtEdge(name: str, context: CfnginContext, mappings: Optional[Dict[str, Dict[str, Any]]] = None, description: Optional[str] = None)[source]

Bases: runway.blueprints.staticsite.staticsite.StaticSite

Auth@Edge Blueprint.

Initialize the Blueprint.

Parameters
  • name – A name for the blueprint.

  • context – Context the blueprint is being executed under.

  • mappings – CloudFormation Mappings to be used in the template.

  • description – Used to describe the resulting CloudFormation template.

AUTH_VARIABLES: Dict[str, BlueprintVariableTypeDef] = {'NonSPAMode': {'default': False, 'description': 'Whether Auth@Edge should omit SPA specific settings', 'type': <class 'bool'>}, 'OAuthScopes': {'default': [], 'description': 'OAuth2 Scopes', 'type': <class 'list'>}, 'PriceClass': {'default': 'PriceClass_100', 'description': 'CF price class for the distribution.', 'type': <class 'str'>}, 'RedirectPathAuthRefresh': {'default': '/refreshauth', 'description': 'The URL path that should handle the JWT refresh request.', 'type': <class 'str'>}, 'RedirectPathSignIn': {'default': '/parseauth', 'description': 'Auth@Edge: The URL that should handle the redirect from Cognito after sign-in.', 'type': <class 'str'>}, 'SignOutUrl': {'default': '/signout', 'description': 'The URL path that you can visit to sign-out.', 'type': <class 'str'>}}
IAM_ARN_PREFIX = 'arn:aws:iam::aws:policy/service-role/'
VARIABLES: Dict[str, BlueprintVariableTypeDef] = {}
create_template()None[source]

Create the Blueprinted template for Auth@Edge.

get_auth_at_edge_lambda_and_ver(title: str, description: str, handle: str, role: troposphere.iam.Role) → Dict[str, Any][source]

Create a lambda function and its version.

Parameters
  • title – The name of the function in PascalCase.

  • description – Description to be displayed in the lambda panel.

  • handle – The underscore separated representation of the name of the lambda. This handle is used to determine the handler for the lambda as well as identify the correct Code hook_data information.

  • role – The Lambda Execution Role.

get_auth_at_edge_lambda(title: str, description: str, handler: str, role: troposphere.iam.Role) → troposphere.awslambda.Function[source]

Create an Auth@Edge lambda resource.

Parameters
  • title – The name of the function in PascalCase.

  • description – Description to be displayed in the lambda panel.

  • handler – The underscore separated representation of the name of the lambda. This handle is used to determine the handler for the lambda as well as identify the correct Code hook_data information.

  • role – The Lambda Execution Role.

add_version(title: str, lambda_function: troposphere.awslambda.Function) → troposphere.awslambda.Version[source]

Create a version association with a Lambda@Edge function.

In order to ensure different versions of the function are appropriately uploaded a hash based on the code of the lambda is appended to the name. As the code changes so will this hash value.

Parameters
  • title – The name of the function in PascalCase.

  • lambda_function – The Lambda function.

get_distribution_options(bucket: troposphere.s3.Bucket, oai: troposphere.cloudfront.CloudFrontOriginAccessIdentity, lambda_funcs: List[troposphere.cloudfront.LambdaFunctionAssociation], check_auth_lambda_version: troposphere.awslambda.Version, http_headers_lambda_version: troposphere.awslambda.Version, parse_auth_lambda_version: troposphere.awslambda.Version, refresh_auth_lambda_version: troposphere.awslambda.Version, sign_out_lambda_version: troposphere.awslambda.Version) → Dict[str, Any][source]

Retrieve the options for our CloudFront distribution.

Keyword Arguments
  • bucket – The bucket resource.

  • oai – The origin access identity resource.

  • lambda_funcs – List of Lambda Function associations.

  • check_auth_lambda_version – Lambda Function Version to use.

  • http_headers_lambda_version – Lambda Function Version to use.

  • parse_auth_lambda_version – Lambda Function Version to use.

  • refresh_auth_lambda_version – Lambda Function Version to use.

  • sign_out_lambda_version – Lambda Function Version to use.

Returns

The CloudFront Distribution Options.