React Terraform Starter Kit screenshot

React Terraform Starter Kit

Author Avatar Theme by Adamjarret
Updated: 5 Apr 2019
11 Stars

Restrict access to S3 files with an AWS API Gateway custom authorizer

Overview

This project offers a streamlined starting point for building AWS microservices, particularly focusing on the integration of API Gateway and custom authorizers to invoke Lambda functions. It sets up a functional architecture that allows for secure access to static files hosted on S3, demanding a password for downloads. With a robust backend configured via Terraform and a user-friendly interface created using React, Redux, and Material-UI, this setup provides a modern approach for developing web applications with solid security measures.

The operation is straightforward: the application utilizes cookies for user authentication, which not only simplify the user experience but also enhance the security of binary file downloads. By enabling cookie handling, the app allows protected resources like images and videos to be accessed similarly to public content, making it a versatile solution for developers looking to balance ease of use with stringent security protocols.

Features

  • Custom Authentication: Utilizes a Lambda function to verify passwords, returning a token that ensures security for user sessions.
  • S3 File Access Controls: Configures an S3 bucket with read-only access to a public folder, allowing for protected downloads of static files.
  • API Gateway Integration: Sets up an API Gateway that serves the web app and handles authentication requests seamlessly.
  • Cookie-Based Security: Employs cookies for session management, automatically sending tokens in requests for accessing protected content.
  • Terraform Configuration: Uses Terraform for managing AWS services, encouraging infrastructure as code for efficient configurations.
  • Modern Tech Stack: Built with industry-standard technologies including Webpack, React, Redux, and Material-UI for a responsive user interface.
  • Multi-Role Permissions: Promotes a security-conscious approach by suggesting multiple Terraform configurations for role-based access control.
  • Easy Setup: Provides clear prerequisites and installation instructions across platforms, simplifying the initial deployment process.