AWS lambda: Update token handling for SnapStart security
Summary
Replaced static AWS_SESSION_TOKEN with dynamic credential fetching to ensure token freshness.
Security assessment
Ensures session tokens remain fresh after SnapStart restores, preventing potential auth failures.
Evidence
+ // Resolve the session token from the credential provider chain so that this
Diff
diff --git a/lambda/latest/dg/with-secrets-manager.md b/lambda/latest/dg/with-secrets-manager.md index d4d7c4831..b2e0e3bdb 100644 --- a//lambda/latest/dg/with-secrets-manager.md +++ b//lambda/latest/dg/with-secrets-manager.md @@ -90 +90 @@ Python - import os + import boto3 @@ -97,0 +98,5 @@ Python + # Resolve the session token from the credential provider chain so that this + # works across all initialization modes, including SnapStart. Resolve inside + # the handler so the token stays fresh after a SnapStart restore. + session_token = boto3.Session().get_credentials().get_frozen_credentials().token + @@ -99 +104 @@ Python - headers = {"X-Aws-Parameters-Secrets-Token": os.environ.get('AWS_SESSION_TOKEN')} + headers = {"X-Aws-Parameters-Secrets-Token": session_token} @@ -152,0 +158 @@ Node.js + import { fromNodeProviderChain } from '@aws-sdk/credential-providers'; @@ -157,0 +164,6 @@ Node.js + + // Resolve the session token from the credential provider chain so that this + // works across all initialization modes, including SnapStart. Resolve inside + // the handler so the token stays fresh after a SnapStart restore. + const { sessionToken } = await fromNodeProviderChain()(); + @@ -163 +175 @@ Node.js - 'X-Aws-Parameters-Secrets-Token': process.env.AWS_SESSION_TOKEN + 'X-Aws-Parameters-Secrets-Token': sessionToken @@ -248,0 +261,5 @@ Java + <dependency> + <groupId>software.amazon.awssdk</groupId> + <artifactId>auth</artifactId> + <version>2.25.0</version> + </dependency> @@ -283,0 +301,2 @@ Java + import software.amazon.awssdk.auth.credentials.DefaultCredentialsProvider; + import software.amazon.awssdk.auth.credentials.AwsSessionCredentials; @@ -290,0 +310 @@ Java + private final DefaultCredentialsProvider credentialsProvider = DefaultCredentialsProvider.create(); @@ -298,0 +319,6 @@ Java + // Resolve the session token from the credential provider chain so that this + // works across all initialization modes, including SnapStart. Resolve inside + // the handler so the token stays fresh after a SnapStart restore. + AwsSessionCredentials credentials = (AwsSessionCredentials) credentialsProvider.resolveCredentials(); + String sessionToken = credentials.sessionToken(); + @@ -301 +327 @@ Java - .header("X-Aws-Parameters-Secrets-Token", System.getenv("AWS_SESSION_TOKEN")) + .header("X-Aws-Parameters-Secrets-Token", sessionToken)