From b0b24447996f602f196677530e9bcdf249d74f6d Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Tue, 2 Jun 2026 17:42:13 -0400 Subject: [PATCH] Add API access logging (audit Day 3: M-18) (#23) Access logging to /aws/apigateway/door-unlock-api (90d) on the HTTP API default stage. Throttling (5 burst / 2 rps) was already present. --- lib/door-unlock-stack.ts | 21 +++++++++++++++++++++ 1 file changed, 21 insertions(+) diff --git a/lib/door-unlock-stack.ts b/lib/door-unlock-stack.ts index 724f6f9..599c656 100644 --- a/lib/door-unlock-stack.ts +++ b/lib/door-unlock-stack.ts @@ -184,6 +184,27 @@ export class DoorUnlockStack extends cdk.Stack { ThrottlingRateLimit: 2, }); + // Access logging (audit M-18). Throttling above was already present. + const apiAccessLogGroup = new logs.LogGroup(this, "ApiAccessLogGroup", { + logGroupName: "/aws/apigateway/door-unlock-api", + retention: logs.RetentionDays.THREE_MONTHS, + removalPolicy: cdk.RemovalPolicy.DESTROY, + }); + defaultStage.addPropertyOverride("AccessLogSettings", { + DestinationArn: apiAccessLogGroup.logGroupArn, + Format: JSON.stringify({ + requestId: "$context.requestId", + ip: "$context.identity.sourceIp", + requestTime: "$context.requestTime", + method: "$context.httpMethod", + routeKey: "$context.routeKey", + status: "$context.status", + protocol: "$context.protocol", + responseLength: "$context.responseLength", + integrationError: "$context.integrationErrorMessage", + }), + }); + httpApi.addRoutes({ path: "/unlock", methods: [apigwv2.HttpMethod.GET],