# Upgrading from 1.24 to 1.26 serverless, AWS signature validation fails when invoking lamda function

**URL:** <https://forum.serverless.com/t/upgrading-from-1-24-to-1-26-serverless-aws-signature-validation-fails-when-invoking-lamda-function/4352>\
**Category:** Serverless Framework\
**Created:** [April 25, 2018, 8:52pm UTC](https://forum.serverless.com/t/upgrading-from-1-24-to-1-26-serverless-aws-signature-validation-fails-when-invoking-lamda-function/4352 "2018-04-25T20:52:43Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![vasudevan-palani](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/vasudevan-palani/32/1896_2.png) [@vasudevan-palani](https://forum.serverless.com/u/vasudevan-palani)\
**Post date:** [April 25, 2018, 8:52pm UTC](https://forum.serverless.com/t/upgrading-from-1-24-to-1-26-serverless-aws-signature-validation-fails-when-invoking-lamda-function/4352/1 "2018-04-25T20:52:43Z")

</div>

Hi,

To set the context to the question the scenario is as below for AWS:

1. API Gateway with lambda integration ( NOT proxy )
2. Has custom authorizer which looks up Bearer token in “Authorization” header.

Serverless.yml file has below configuration

```
hello:
    handler: handler.hello
    events:
      - http:
          name: ${opt:stage}-jstest
          path: /
          method: get
          cors:
           origins:
             - '*'
           headers:
             - Content-Type
             - X-Amz-Date
             - Authorization
             - X-Api-Key
             - X-Amz-Security-Token
           methods:
             - GET
             - OPTIONS
          integration: lambda
          authorizer:
              name: authorizerFunction
              resultTtlInSeconds: 300
              identitySource: method.request.header.Authorization
          request:
            parameters:
             headers:
               Authorization : true
```

Issue statement: When I add headers in request parameter to serverless.yml file, the header mapping is created for both method and integration ( in 1.26). However, the behaviour in version 1.24.1. is, it creates only in method but not in integration.

With the behavior as in 1.26, and with headers added to request parameters, the error we get when tested is as shown below.

“The request signature we calculated does not match the signature you provided. Check your AWS Secret Access Key and signing method. Consult the service documentation for details.”

Question: Is there anyway to add the request parameter headers only to method and not to integration?

Thanks  
-Vasu

---

<div class="post-metadata">

**Author:** ![jagdish-176](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/jagdish-176/32/1900_2.png) [@jagdish-176](https://forum.serverless.com/u/jagdish-176)\
**Post date:** [April 26, 2018, 9:34am UTC](https://forum.serverless.com/t/upgrading-from-1-24-to-1-26-serverless-aws-signature-validation-fails-when-invoking-lamda-function/4352/2 "2018-04-26T09:34:40Z")

</div>

I’m also facing same issue.

We need to use existing apiGateway ([https://github.com/serverless/serverless/pull/4247](https://github.com/serverless/serverless/pull/4247)) as we ran out of 200 resource limit, so migrated to new version 1.26.1

If we deploy with this version it gives internal server error.  
Guys, help will be really appreciated.

---

<div class="post-metadata">

**Author:** ![aditmalik](https://avatars.discourse-cdn.com/v4/letter/a/9de053/32.png) [@aditmalik](https://forum.serverless.com/u/aditmalik)\
**Post date:** [April 26, 2018, 6:36pm UTC](https://forum.serverless.com/t/upgrading-from-1-24-to-1-26-serverless-aws-signature-validation-fails-when-invoking-lamda-function/4352/3 "2018-04-26T18:36:53Z")

</div>

![image](https://canada1.discourse-cdn.com/flex036/uploads/serverless/original/2X/6/638152755f4000cf78a7d473768876acce1cfe26.png)

Here is the difference in template generated in both cases, for @jagdish-176 issue.

The RequestParameters Section is new, which was not there earlier.

---

<div class="post-metadata">

**Author:** ![aditmalik](https://avatars.discourse-cdn.com/v4/letter/a/9de053/32.png) [@aditmalik](https://forum.serverless.com/u/aditmalik)\
**Post date:** [April 26, 2018, 7:34pm UTC](https://forum.serverless.com/t/upgrading-from-1-24-to-1-26-serverless-aws-signature-validation-fails-when-invoking-lamda-function/4352/4 "2018-04-26T19:34:34Z")

</div>

![image](https://canada1.discourse-cdn.com/flex036/uploads/serverless/original/2X/5/500776d6b3c389fc9f37c20f18485ffe2a5c663e.png)

This code is introduces in 1.26 which is not in 1.24  
If I comment it in the plugin and use it, what could be the effect.

Please note request parameters are already added in the properties section

line: 15 in $/serverless-master\lib\plugins\aws\package\compile\events\apiGateway\lib\method\index.js  
const requestParameters = (event.http.request && event.http.request.parameters) || {};

There should be a separate flag for this?

Regards,  
Adit

---

<div class="post-metadata">

**Author:** ![vasudevan-palani](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/vasudevan-palani/32/1896_2.png) [@vasudevan-palani](https://forum.serverless.com/u/vasudevan-palani)\
**Post date:** [April 26, 2018, 7:45pm UTC](https://forum.serverless.com/t/upgrading-from-1-24-to-1-26-serverless-aws-signature-validation-fails-when-invoking-lamda-function/4352/5 "2018-04-26T19:45:03Z")

</div>

@aditmalik, I believe the issue i mentioned is exactly because of this section of code. Probably we should allow the user to choose if he wants to propagate the mapping to integration request too.

---

<div class="post-metadata">

**Author:** ![bill](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/bill/32/1072_2.png) [@bill](https://forum.serverless.com/u/bill)\
**Post date:** [April 27, 2018, 1:03am UTC](https://forum.serverless.com/t/upgrading-from-1-24-to-1-26-serverless-aws-signature-validation-fails-when-invoking-lamda-function/4352/6 "2018-04-27T01:03:22Z")

</div>

Seems this was done with the PR ([https://github.com/serverless/serverless/pull/4665](https://github.com/serverless/serverless/pull/4665))

---

<div class="post-metadata">

**Author:** ![aditmalik](https://avatars.discourse-cdn.com/v4/letter/a/9de053/32.png) [@aditmalik](https://forum.serverless.com/u/aditmalik)\
**Post date:** [April 27, 2018, 2:14am UTC](https://forum.serverless.com/t/upgrading-from-1-24-to-1-26-serverless-aws-signature-validation-fails-when-invoking-lamda-function/4352/7 "2018-04-27T02:14:05Z")

</div>

anyupdate, if this is going to be changed or modified or removed

---

<div class="post-metadata">

**Author:** ![bill](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/bill/32/1072_2.png) [@bill](https://forum.serverless.com/u/bill)\
**Post date:** [April 27, 2018, 2:58am UTC](https://forum.serverless.com/t/upgrading-from-1-24-to-1-26-serverless-aws-signature-validation-fails-when-invoking-lamda-function/4352/8 "2018-04-27T02:58:58Z")

</div>

can you raise an issue with details directly to [github.com/serverless/serverless](http://github.com/serverless/serverless) for this big?

---

<div class="post-metadata">

**Author:** ![aditmalik](https://avatars.discourse-cdn.com/v4/letter/a/9de053/32.png) [@aditmalik](https://forum.serverless.com/u/aditmalik)\
**Post date:** [April 27, 2018, 3:16am UTC](https://forum.serverless.com/t/upgrading-from-1-24-to-1-26-serverless-aws-signature-validation-fails-when-invoking-lamda-function/4352/9 "2018-04-27T03:16:36Z")

</div>

> <https://github.com/serverless/serverless/issues/4939>
>
> https://forum.serverless.com/t/upgrading-from-1-24-to-1-26-serverless-aws-signat…ure-validation-fails-when-invoking-lamda-function/4352
> 
> From 1.26 onward in case of Lambda integrations (Legacy) calls are failing.
> I looked at the code 
> line: 91 in $/serverless-master\\lib\\plugins\\aws\\package\\compile\\events\\apiGateway\\lib\\method\\integration.js
> request parameters are again added in the integration section of cloud formation template.
> Which enable integration request to specify request parameter, this is not in the case of previous versions of plugin.
> 
> Anyupdates if this could be an optional or any workarounds

Raised an issue in serverless

---

<div class="post-metadata">

**Author:** ![vasudevan-palani](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/vasudevan-palani/32/1896_2.png) [@vasudevan-palani](https://forum.serverless.com/u/vasudevan-palani)\
**Post date:** [April 27, 2018, 11:15am UTC](https://forum.serverless.com/t/upgrading-from-1-24-to-1-26-serverless-aws-signature-validation-fails-when-invoking-lamda-function/4352/10 "2018-04-27T11:15:15Z")

</div>

I raised an issue with AWS and they answered as below, " The internal server error" was raised because of “Signature mimatch” between API Gateway and Lambda. As API Gateway too uses “Authorization” header , the header gets corrupted if users too use it. AWS advised me not to use this header and use a different name.

I changed my header from “Authorization” to “AuthToken” and it worked in 1.26.1 serverless. Posting this is it can help anyone.

I believe this is just a work around and sls needs to fix this.

Thanks.  
-Vasu

---

<div class="post-metadata">

**Author:** ![aditmalik](https://avatars.discourse-cdn.com/v4/letter/a/9de053/32.png) [@aditmalik](https://forum.serverless.com/u/aditmalik)\
**Post date:** [April 27, 2018, 2:24pm UTC](https://forum.serverless.com/t/upgrading-from-1-24-to-1-26-serverless-aws-signature-validation-fails-when-invoking-lamda-function/4352/11 "2018-04-27T14:24:15Z")

</div>

> [@vasudevan-palani](#):
>
> Authorization

Authorization, is a standard header tag, i don’t think renaming it right.

---

<div class="post-metadata">

**Author:** ![vasudevan-palani](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/vasudevan-palani/32/1896_2.png) [@vasudevan-palani](https://forum.serverless.com/u/vasudevan-palani)\
**Post date:** [April 27, 2018, 2:46pm UTC](https://forum.serverless.com/t/upgrading-from-1-24-to-1-26-serverless-aws-signature-validation-fails-when-invoking-lamda-function/4352/12 "2018-04-27T14:46:36Z")

</div>

I agree, It would also require all your consumers to change their headers. I too gonna wait for sls to fix it.

---

<div class="post-metadata">

**Author:** ![bill](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/bill/32/1072_2.png) [@bill](https://forum.serverless.com/u/bill)\
**Post date:** [April 29, 2018, 11:49am UTC](https://forum.serverless.com/t/upgrading-from-1-24-to-1-26-serverless-aws-signature-validation-fails-when-invoking-lamda-function/4352/13 "2018-04-29T11:49:27Z")

</div>

Authorization is standard header tag, not mean you have to use the name. You can define to any other names if you want to do.

```
identitySource: method.request.header.x-abc-xyz
```

---

<div class="post-metadata">

**Author:** ![vasudevan-palani](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/vasudevan-palani/32/1896_2.png) [@vasudevan-palani](https://forum.serverless.com/u/vasudevan-palani)\
**Post date:** [June 21, 2018, 7:41pm UTC](https://forum.serverless.com/t/upgrading-from-1-24-to-1-26-serverless-aws-signature-validation-fails-when-invoking-lamda-function/4352/14 "2018-06-21T19:41:58Z")

</div>

I have a written a serverless plugin for workaround while the team fixes it permanently.

> **[GitHub - vasudevan-palani/serverless-fix-apigw-int](https://github.com/vasudevan-palani/serverless-fix-apigw-int)**
>
> Contribute to vasudevan-palani/serverless-fix-apigw-int development by creating an account on GitHub.

You can do

npm install serverless-fix-apigw-int  
Add this plugin to serverless.yml file.  
deploy  
Thanks

---

<div class="post-metadata">

**Author:** ![anil121786](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/anil121786/32/4798_2.png) [@anil121786](https://forum.serverless.com/u/anil121786)\
**Post date:** [November 28, 2020, 7:41pm UTC](https://forum.serverless.com/t/upgrading-from-1-24-to-1-26-serverless-aws-signature-validation-fails-when-invoking-lamda-function/4352/15 "2020-11-28T19:41:01Z")

</div>

I have got it resolved by configuring the aws credentials using the below cmds:

1. serverless config credentials --provider aws -k \<your\_access\_key\_id\_here\> -s \<your\_secret\_access\_key\_here\>

2. export AWS\_ACCESS\_KEY\_ID="\<your\_access\_key\_id\_here\>"  
export AWS\_SECRET\_ACCESS\_KEY="\<your\_secret\_access\_key\_here\>"

---

<div class="post-metadata">

**Author:** ![lapdatcamera](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/lapdatcamera/32/4805_2.png) [@lapdatcamera](https://forum.serverless.com/u/lapdatcamera)\
**Post date:** [December 1, 2020, 1:49pm UTC](https://forum.serverless.com/t/upgrading-from-1-24-to-1-26-serverless-aws-signature-validation-fails-when-invoking-lamda-function/4352/16 "2020-12-01T13:49:42Z")

</div>

If we deploy with this version it gives internal server error
