Construct to create a private asset S3 bucket. A cognito token can be used to allow access to he S3 asset.
Project description
cdk-private-asset-bucket
A construct to create a private asset S3 bucket. Cognito will be used for token validation with Lambda@Edge.
Architecture
Example
import { PrivateAssetBucket } from 'cdk-private-assets-bucket';
...
const userPool = new cognito.UserPool(stack, 'userPool', {
removalPolicy: core.RemovalPolicy.DESTROY,
});
const userPoolWebClient = new cognito.UserPoolClient(stack, 'userPoolWebClient', {
userPool: userPool,
generateSecret: false,
preventUserExistenceErrors: true,
authFlows: {
adminUserPassword: true,
userPassword: true,
},
oAuth: {
flows: {
authorizationCodeGrant: false,
implicitCodeGrant: true,
},
},
});
const privateAssetBucket = new PrivateAssetBucket(stack, 'privateAssetBucket', {
userPoolId: userPool.userPoolId,
userPoolClientId: userPoolWebClient.userPoolClientId,
});
new core.CfnOutput(stack, 'AssetBucketName', {
value: privateAssetBucket.assetBucketName,
});
new core.CfnOutput(stack, 'AssetBucketCloudfrontUrl', {
value: privateAssetBucket.assetBucketCloudfrontUrl,
});
Properties
Test PrivateBucketAsset
If you forged / cloned that repo you can test directly from here. Don't forget to init with:
yarn install
Create a test cdk stack with one of the following:
yarn cdk deploy
yarn cdk deploy --watch
yarn cdk deploy --require-approval never
- Upload a picture named like pic.png to the private asset bucket
- Create a user pool user and get / save the token:
USER_POOL_ID=us-east-1_0Aw1oPvD6
CLIENT_ID=3eqcgvghjbv4d5rv32hopmadu8
USER_NAME=martindev
USER_PASSWORD=M@rtindev1
REGION=us-east-1
CFD=d1f2bfdek3mzi7.cloudfront.net
aws cognito-idp admin-create-user --user-pool-id $USER_POOL_ID --username $USER_NAME --region $REGION
aws cognito-idp admin-set-user-password --user-pool-id $USER_POOL_ID --username $USER_NAME --password $USER_PASSWORD --permanent --region $REGION
ACCESS_TOKEN=$(aws cognito-idp initiate-auth --auth-flow USER_PASSWORD_AUTH --client-id $CLIENT_ID --auth-parameters USERNAME=$USER_NAME,PASSWORD=$USER_PASSWORD --region $REGION | jq -r '.AuthenticationResult.AccessToken')
echo "curl --location --request GET "https://$CFD/pic.png" --cookie "Cookie: token=$ACCESS_TOKEN""
- You can use the curl for importing in Postman. but it looks like Postman can't import the cookie. So you need to set the cookie manually in Postman!
- In Postman you should see your picture :)
Planned Features
- Migrating to cdk v2. If you know a cool workflow how to continuously support v1 and v2 let me know!
- Support S3 bucket import ootb.
- Support custom authorizer
- Leverage Cloudfront Function for cheaper costs
Misc
- There is currently my aws-cdk PR open for importing the Typescript Lambda@Edge interface https://github.com/aws/aws-cdk/pull/18836
Thanks To
- Crespo Wang for his pioneer work regarding private S3 assets https://javascript.plainenglish.io/use-lambda-edge-jwt-to-secure-s3-bucket-dcca6eec4d7e
- As always to the amazing CDK / Projen Community. Join us on Slack!
- Projen project and the community around it
- To you for checking this out. Check me out and perhaps give me feedback https://martinmueller.dev
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Close
Hashes for cdk-private-asset-bucket-1.143.5.tar.gz
Algorithm | Hash digest | |
---|---|---|
SHA256 | 544f726548decaf2c8615ee7d57d9659a3fd9d5ab667c28954b2d84c714aa839 |
|
MD5 | 5a52251af230827d67630998d881e442 |
|
BLAKE2b-256 | 140981a2577ccc03291bb46e4a1e10acec6071a22ee8239c4b3fee0a5abacf68 |
Close
Hashes for cdk_private_asset_bucket-1.143.5-py3-none-any.whl
Algorithm | Hash digest | |
---|---|---|
SHA256 | d895c77edc609e039822fd4c654bb8b71d29158ffd0bf6d37a90096a151495f3 |
|
MD5 | 8ad6d17344ca5dc0abfc11e08b24a642 |
|
BLAKE2b-256 | aea9fdbd3bd4c1a4acc9d63fd31a9c62190a6ecc8cb3b34d6eaf068b4e7d66fd |