Repository navigation
Conversation
Generated API Gateway authorizer handlers previously logged a conversion failure for [FromHeader], [FromQuery] and [FromRoute] parameters and then invoked the authorizer method with the parameter set to default(T). They now return a deny response matching the authorizer's return type without invoking the authorizer method.
Contributor
There was a problem hiding this comment.
Warning
Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.
Copilot review overview
3 open findings
HasBoundParameters()only considers[FromHeader]/[FromQuery]/[FromRoute], but the template also… · New The generated deny-response code relies on unqualifiedList<>andHashSet<>. That makes the… · New The temp project directory is deleted before emitting/validating compilation results. If either… · New
What changed in this PR
Updates the Annotations source generator so API Gateway authorizer handlers fail closed when parameter binding/conversion fails, aligning behavior with non-authorizer handlers and preventing “default(T)” from reaching user code.
Changes:
- Track conversion failures during authorizer parameter binding and deny without invoking the user authorizer.
- Generate deny responses appropriate to the authorizer’s return type (IAuthorizerResult, simple response, IAM policy, or throw Unauthorized).
- Add targeted generator+runtime compilation tests and update snapshots.
| File | Description |
|---|---|
| Libraries/src/Amazon.Lambda.Annotations.SourceGenerator/Templates/AuthorizerSetupParameters.tt | Emits __bindingFailed__ tracking and a deny check after parameter binding. |
| Libraries/src/Amazon.Lambda.Annotations.SourceGenerator/Templates/AuthorizerSetupParameters.cs | Updates preprocessed T4 output to match the template changes. |
| Libraries/src/Amazon.Lambda.Annotations.SourceGenerator/Templates/AuthorizerSetupParametersCode.cs | Adds helper logic to detect bound parameters and generate deny responses per return type. |
| Libraries/src/Amazon.Lambda.Annotations.SourceGenerator/TypeFullNames.cs | Adds missing full names for APIGW v2 IAM response and policy types. |
| Libraries/test/.../AuthorizerBindingFailureTests.cs | New integration-style tests that run the generator, compile output, and validate deny behavior + no user invocation. |
| Libraries/test/.../Snapshots/Authorizer_Generated.g.cs | Snapshot updates to include binding-failure deny path. |
| .autover/changes/*.json | Records a patch changelog entry for the behavior change. |
🧠 Review effort: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Copilot stopped reviewing on behalf of
normj due to an error
October 8, 2026 21:19
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Issue #, if available:
Description of changes:
Generated API Gateway authorizer handlers bind
[FromHeader],[FromQuery]and[FromRoute]parameters (and the REST API TOKENAuthorizationToken) withConvert.ChangeType. When conversion failed, for exampleabcfor alongparameter, the generated code logged the error and then still invoked the authorizer method with the parameter set todefault(T). The non-authorizer API Gateway template already returns a 400 in this case; the authorizer template had no equivalent.Generated authorizers now fail closed: if any bound value fails to convert, the handler returns a deny response without invoking the authorizer method. The deny response matches the authorizer's return type:
IAuthorizerResultAuthorizerResults.Deny()serialized with the same format and method/route ARN as the normal pathAPIGatewayCustomAuthorizerV2SimpleResponseIsAuthorized = falseAPIGatewayCustomAuthorizerResponse/APIGatewayCustomAuthorizerV2IamResponseDenypolicy forexecute-api:Invokeon the method/route ARNthrow new Exception("Unauthorized")The check is only emitted when the method has bound parameters. Missing values are unchanged and still bind as
default(T).Changes
AuthorizerSetupParameters.tt/.cs: track a__bindingFailed__flag in each conversion catch block and emit the deny check after parameter binding. The preprocessed.cswas updated by hand to match the.tt, so it's worth regenerating in Visual Studio before merging.AuthorizerSetupParametersCode.cs: generate the deny response for each return type.TypeFullNames.cs: addAPIGatewayCustomAuthorizerV2IamResponseandAPIGatewayCustomAuthorizerPolicy.AuthorizerBindingFailureTests: runs the generator, compiles the output, and invokes the generated handlers. It covers malformed header, query, route and token values across all response shapes, and asserts that the request is denied and the authorizer method isn't invoked. A control test checks that well-formed values still reach the method. Without the template change, 9 of the 10 tests fail.Testing
Amazon.Lambda.Annotations.SourceGenerators.Tests: 593/593 passing on net8.0 and net10.0.By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.