Skip to content

Accept a single Resource string in local authorizer policies - #2197

Open
kwy404 wants to merge 1 commit into
aws:masterfrom
kwy404:fix-local-authorizer-string-resource
Open

kwy404 wants to merge 1 commit into
aws:masterfrom
kwy404:fix-local-authorizer-string-resource

Conversation

@kwy404

@kwy404 kwy404 commented Sep 25, 2026

Copy link
Copy Markdown

Issue #, if available: N/A

Description of changes:

A policy statement returned by a custom authorizer can use a single string for Resource instead of a list. In local mode that string was iterated character by character, so the ARN never matched and the request was rejected with a 403 even though API Gateway allows it. This treats a string Resource as a one-item list, and adds a test and a changelog entry.

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

A policy statement returned by a custom authorizer can use a single
string for Resource instead of a list. In local mode the string was
iterated character by character, so the ARN never matched and the
request was rejected with a 403 even though API Gateway allows it.
@kwy404
kwy404 requested a review from a team as a code owner September 25, 2026 01:47

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant