Post

Visualizzazione dei post da agosto, 2024

Using Apache HttpClient to retrieve Cognito Token for Api Gateway

Immagine
  To secure your Api Gateway, there is the option to add Cognito as Authorizer. It is very easy to setup especially if you will follow the GUI instruction from console. This is a very common setup: you have your Cognito User Pool where you have create the UI to admit clients to login and check their credentials. The UI can be easily managed because you can integrate it and setup your home Application as redirect URI, so they can be see the home page right after login submit. Now let's suppose you have an Api Gateway and the same user pool from Cognito is used to allow users to access that. This means that: users have to insert credentials obtain the auth code call the oauth2 obtain the token add it to Authorization header Usually we do this using SDK from AWS, but I want to experiment an alternative way of do this. POSTMAN     If you check on the internet you will see that there are many examples of Postman Cognito Oauth, where you can set up all the configuration and cli...