mirror of
https://github.com/Sea-Haven-Industries/seahaven-account-baseline.git
synced 2026-08-04 16:56:14 +00:00
fix(iam): allow API Gateway authorizer role passing
This commit is contained in:
parent
5d0e8480d4
commit
c09cf1110d
1 changed files with 13 additions and 0 deletions
|
|
@ -1243,3 +1243,16 @@ Resources:
|
||||||
StringEquals:
|
StringEquals:
|
||||||
"iam:PassedToService": "lambda.amazonaws.com"
|
"iam:PassedToService": "lambda.amazonaws.com"
|
||||||
|
|
||||||
|
# API Gateway assumes SAM authorizer invocation roles. Keep this
|
||||||
|
# separate from Lambda PassRole so each target service and role
|
||||||
|
# pattern remains independently constrained.
|
||||||
|
- Sid: IAMPassAuthorizerRole
|
||||||
|
Effect: Allow
|
||||||
|
Action:
|
||||||
|
- iam:PassRole
|
||||||
|
Resource:
|
||||||
|
- !Sub "arn:aws:iam::${AWS::AccountId}:role/cfn-managed/*AuthorizerInvokeRole-*"
|
||||||
|
Condition:
|
||||||
|
StringEquals:
|
||||||
|
"iam:PassedToService": "apigateway.amazonaws.com"
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue