Decide access from the claims
You maintain an API that serves quarterly reports. Four requests arrive together, each carrying a bearer token, and each asking for the same thing: GET /reports/q3-summary, which needs the reports/read scope.
Open the Token claims console. Start on Request log to see what your API records for every request, then switch to Decoded claims and read each token against the panel showing what your API expects.
Every signature here is valid. Verified is not the same as appropriate.
Only one of these four tokens should be allowed to call GET /reports.
Which one?
Bài tập này là một phần của khóa học
Using AWS Security for Developers
Bài tập tương tác thực hành
Biến lý thuyết thành hành động với một trong các bài tập tương tác của chúng tôi
Bắt đầu bài tập