From c09cf1110db657ad3c241afbcc069b15e4f0b079 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Mon, 3 Aug 2026 14:38:39 -0400 Subject: [PATCH] fix(iam): allow API Gateway authorizer role passing --- lib/deploy-substrate/deploy-substrate.template.yaml | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/lib/deploy-substrate/deploy-substrate.template.yaml b/lib/deploy-substrate/deploy-substrate.template.yaml index 301af15..aa91a40 100644 --- a/lib/deploy-substrate/deploy-substrate.template.yaml +++ b/lib/deploy-substrate/deploy-substrate.template.yaml @@ -1243,3 +1243,16 @@ Resources: StringEquals: "iam:PassedToService": "lambda.amazonaws.com" + # API Gateway assumes SAM authorizer invocation roles. Keep this + # separate from Lambda PassRole so each target service and role + # pattern remains independently constrained. + - Sid: IAMPassAuthorizerRole + Effect: Allow + Action: + - iam:PassRole + Resource: + - !Sub "arn:aws:iam::${AWS::AccountId}:role/cfn-managed/*AuthorizerInvokeRole-*" + Condition: + StringEquals: + "iam:PassedToService": "apigateway.amazonaws.com" +