AWS appsync: AppSync: set clientId when JWT issuer is shared/non-unique
Summary
Adds a note warning that shared issuers such as Cognito identity pools have non-unique issuer URLs, so clientId must be set to restrict access to tokens issued for your own pool or application.
Security assessment
The note documents an authorization hardening step: with a shared issuer URL such as https://cognito-identity.amazonaws.com, omitting clientId would allow tokens issued to other applications/pools to be accepted by the API. It is preventive guidance for a misconfiguration rather than a fix for a specific incident or CVE, so it is security documentation at medium severity.
Evidence
+For shared issuers, such as Amazon Cognito identity pools, the issuer URL (for example, `https://cognito-identity.amazonaws.com`) is not unique to your pool or application. In this case, be sure to set `clientId`, because it restricts access to tokens issued for your pool or application.
Diff
diff --git a/appsync/latest/devguide/security-authz.md b/appsync/latest/devguide/security-authz.md index 4a1b0184f..0d6d15360 100644 --- a//appsync/latest/devguide/security-authz.md +++ b//appsync/latest/devguide/security-authz.md @@ -477,0 +478,4 @@ To validate multiple client IDs use the pipeline operator (“|”) which is an +###### Note + +For shared issuers, such as Amazon Cognito identity pools, the issuer URL (for example, `https://cognito-identity.amazonaws.com`) is not unique to your pool or application. In this case, be sure to set `clientId`, because it restricts access to tokens issued for your pool or application. +