我试图了解AWS Api网关中的授权者。据我所知,如果在authorizer中发生逻辑异常,那么我们肯定会得到401,消息未经授权。是否可能返回错误的请求响应或无法处理的实体响应?
我发现授权者的工作有点奇怪:
1) custom authorizers in Amazon API Gateway 500 error
2个) https://forums.aws.amazon.com/message.jspa?messageID=753817
这是可能的。有多种解决方案。
lambda函数可以抛出一个自定义异常,您可以执行 API网关中基于异常的捕获以发送400状态代码。
使用拒绝响应,但在上下文中有拒绝的原因。 当发生拒绝时,代码可以检查上下文中的原因 返回适当的响应。
有关异常映射,请参阅以下链接 https://docs.aws.amazon.com/apigateway/latest/developerguide/handle-errors-in-lambda-integration.html#handle-custom-errors-in-lambda-integration
http://awspapers.blogspot.com/2018/08/integrate-api-with-lambda-part-5.html