Construct to create a private asset S3 bucket. A cognito token can be used to allow access to he S3 asset.
Project description
cdk-private-asset-bucket
A construct to create a private asset S3 bucket. Cognito will be used for token validation with Lambda@Edge.
Architecture
Curious how I did the diagram? Have a look here https://martinmueller.dev/cdk-dia-eng .
Example
import { PrivateAssetBucket } from 'cdk-private-assets-bucket';
...
const userPool = new cognito.UserPool(stack, 'userPool', {
removalPolicy: core.RemovalPolicy.DESTROY,
});
const userPoolWebClient = new cognito.UserPoolClient(stack, 'userPoolWebClient', {
userPool: userPool,
generateSecret: false,
preventUserExistenceErrors: true,
authFlows: {
adminUserPassword: true,
userPassword: true,
},
oAuth: {
flows: {
authorizationCodeGrant: false,
implicitCodeGrant: true,
},
},
});
const privateAssetBucket = new PrivateAssetBucket(stack, 'privateAssetBucket', {
userPoolId: userPool.userPoolId,
userPoolClientId: userPoolWebClient.userPoolClientId,
tokenUse: 'access',
});
new core.CfnOutput(stack, 'AssetBucketName', {
value: privateAssetBucket.assetBucketName,
});
new core.CfnOutput(stack, 'AssetBucketCloudfrontUrl', {
value: privateAssetBucket.assetBucketCloudfrontUrl,
});
Properties
Test PrivateBucketAsset
If you forged / cloned that repo you can test directly from here. Don't forget to init with:
yarn install
Create a test cdk stack with one of the following:
yarn cdk deploy
yarn cdk deploy --watch
yarn cdk deploy --require-approval never
- Upload a picture named like pic.png to the private asset bucket
- Create a user pool user and get / save the token:
USER_POOL_ID=us-east-1_0Aw1oPvD6
CLIENT_ID=3eqcgvghjbv4d5rv32hopmadu8
USER_NAME=martindev
USER_PASSWORD=M@rtindev1
REGION=us-east-1
CFD=d1f2bfdek3mzi7.cloudfront.net
aws cognito-idp admin-create-user --user-pool-id $USER_POOL_ID --username $USER_NAME --region $REGION
aws cognito-idp admin-set-user-password --user-pool-id $USER_POOL_ID --username $USER_NAME --password $USER_PASSWORD --permanent --region $REGION
ACCESS_TOKEN=$(aws cognito-idp initiate-auth --auth-flow USER_PASSWORD_AUTH --client-id $CLIENT_ID --auth-parameters USERNAME=$USER_NAME,PASSWORD=$USER_PASSWORD --region $REGION | jq -r '.AuthenticationResult.AccessToken')
echo "curl --location --request GET "https://$CFD/pic.png" --cookie "Cookie: token=$ACCESS_TOKEN""
- You can use the curl for importing in Postman. but it looks like Postman can't import the cookie. So you need to set the cookie manually in Postman!
- In Postman you should see your picture :)
- For Debugging the Lambda@Edge with Cloudwatch go to the AWS Console --> Cloudwatch --> Log groups --> switch to the region you are closest to --> figure out which log group is correct
Planned Features
- Support custom authorizer
- Leverage Cloudfront Function for cheaper costs
Misc
- There is currently my aws-cdk PR open for importing the Typescript Lambda@Edge interface https://github.com/aws/aws-cdk/pull/18836
git tag -a v2.16.0 -m "prepare tag version" && git push --tags
Thanks To
- Crespo Wang for his pioneer work regarding private S3 assets https://javascript.plainenglish.io/use-lambda-edge-jwt-to-secure-s3-bucket-dcca6eec4d7e
- As always to the amazing CDK / Projen Community. Join us on Slack!
- Projen project and the community around it.
- To you for checking this out. Check me out and perhaps give me feedback https://martinmueller.dev .
I love to work on Content Management Open Source projects. A lot from my stuff you can already use on https://github.com/mmuller88 . If you like my work there and my blog posts, please consider supporting me on Patreon:
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
File details
Details for the file cdk-private-asset-bucket-2.24.0.tar.gz
.
File metadata
- Download URL: cdk-private-asset-bucket-2.24.0.tar.gz
- Upload date:
- Size: 10.0 MB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/4.0.0 CPython/3.10.4
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | 5b7ac73eeda3606cc3a074d22519707046d04c1faff7f00bc8ee2f476898ecf9 |
|
MD5 | c33af6ab58fd71ef7cd57cb3ab4731ae |
|
BLAKE2b-256 | 28d5729b6c9d9640c4917f15932290c5775642d8e0bfa702f63484016e6cad96 |
File details
Details for the file cdk_private_asset_bucket-2.24.0-py3-none-any.whl
.
File metadata
- Download URL: cdk_private_asset_bucket-2.24.0-py3-none-any.whl
- Upload date:
- Size: 10.0 MB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/4.0.0 CPython/3.10.4
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | 26718b3ce2bfc9907eaf030d6f288c05d22fb214ac757dfda4be574b95166282 |
|
MD5 | 72ebf038a99d4f61a0d0c3103396ba67 |
|
BLAKE2b-256 | 85842f2aec86b733a42b146077982eda74249f83773122682e9bf06cfc9fa951 |