AWS appsync: AppSync Event API: set clientId for shared JWT issuers
Summary
Adds the same note for Event API authorization, stating that shared issuer URLs (e.g., Cognito identity pools) are not unique and clientId must be set to restrict token acceptance to your pool or application.
Security assessment
Identical authorization-hardening guidance applied to AppSync Event API auth configuration: an unset clientId with a shared issuer could permit tokens minted for other applications to be accepted, enabling unauthorized access. Documentation-level hardening guidance, not a fix for a named vulnerability.
Evidence
+For shared issuers, such as Amazon Cognito identity pools, the issuer URL (for example, `https://cognito-identity.amazonaws.com`) is not unique to your pool or application. In this case, be sure to set `clientId`, because it restricts access to tokens issued for your pool or application.
Diff
diff --git a/appsync/latest/eventapi/configure-event-api-auth.md b/appsync/latest/eventapi/configure-event-api-auth.md index 60e04cec2..eb4426969 100644 --- a//appsync/latest/eventapi/configure-event-api-auth.md +++ b//appsync/latest/eventapi/configure-event-api-auth.md @@ -325,0 +326,4 @@ To validate multiple client IDs use the pipeline operator (“|”) which is an +###### Note + +For shared issuers, such as Amazon Cognito identity pools, the issuer URL (for example, `https://cognito-identity.amazonaws.com`) is not unique to your pool or application. In this case, be sure to set `clientId`, because it restricts access to tokens issued for your pool or application. +