View a markdown version of this page

授權流程 - Amazon Bedrock AgentCore

本文為英文版的機器翻譯版本,如內容有任何歧義或不一致之處,概以英文版為準。

授權流程

Amazon Bedrock AgentCore Gateway 會針對傳入請求評估 Cedar 政策。本節說明授權資訊如何從請求流向政策評估。

請求處理

Amazon Bedrock AgentCore Gateway 會處理每個請求的兩個關鍵資訊:

  1. JWT 字符 - 包含有關使用者的 OAuth 宣告:

    { "sub": "12345678-1234-1234-1234-123456789012", "iss": "https://cognito-idp.us-east-1.amazonaws.com/us-east-1_Vg2efaoGO", "username": "refund-agent", "scope": "aws.cognito.signin.user.admin refund:write", "role": "admin", "department": "finance" }
  2. MCP 工具呼叫請求 - 實際的工具調用:

    { "jsonrpc": "2.0", "id": 1, "method": "tools/call", "params": { "name": "RefundTool___process_refund", "arguments": { "orderId": "12345", "amount": 450, "reason": "Defective product" } } }

Cedar 授權請求

Gateway 從這兩個來源擷取資訊,並建構 Cedar 授權請求。

完成授權請求:

{ "principal": "AgentCore::OAuthUser::\"12345678-1234-1234-1234-123456789012\"", "action": "AgentCore::Action::\"RefundTool___process_refund\"", "resource": "AgentCore::Gateway::\"arn:aws:bedrock-agentcore:us-west-2:123456789012:gateway/refund-gateway\"", "context": { "input": { "orderId": "12345", "amount": 450, "reason": "Defective product" } } }

元件:

Principal

從 JWT 字符的子宣告建立:

AgentCore::OAuthUser::"12345678-1234-1234-1234-123456789012"
Action

從工具名稱擷取:

AgentCore::Action::"RefundTool___process_refund"
資源

Gateway 執行個體:

AgentCore::Gateway::"arn:aws:bedrock-agentcore:us-west-2:123456789012:gateway/refund-gateway"
Context

包含工具引數:

{ "input": { "orderId": "12345", "amount": 450, "reason": "Defective product" } }

實體存放區 - JWT 宣告會以標籤形式存放在 OAuthUser 實體上:

{ "uid": { "type": "AgentCore::OAuthUser", "id": "12345678-1234-1234-1234-123456789012" }, "attrs": { "id": "12345678-1234-1234-1234-123456789012" }, "tags": { "username": "refund-agent", "iss": "https://cognito-idp.us-east-1.amazonaws.com/us-east-1_Vg2efaoGO", "scope": "aws.cognito.signin.user.admin refund:write", "role": "admin", "department": "finance" } }

暫時政策的工作階段內容

當x-amzn-bedrock-agentcore-policy-session-id標頭存在時,閘道會在傳遞給政策引擎的授權請求中包含工作階段內容。工作階段內容提供目前工作階段的累積動作歷史記錄。時間政策規則會使用此歷史記錄評估一段時間內的限制條件。

{ "principal": "AgentCore::OAuthUser::\"12345678-1234-1234-1234-123456789012\"", "action": "AgentCore::Action::\"PaymentTool___transfer_funds\"", "resource": "AgentCore::Gateway::\"arn:aws:bedrock-agentcore:us-west-2:123456789012:gateway/my-gateway\"", "context": { "input": { "amount": 500, "recipient": "account-789" } }, "sessionId": "12345678-1234-1234-1234-123456789012" }

sessionId 欄位會將目前的請求連結至其工作階段歷史記錄。政策引擎會解析工作階段狀態,並根據累積的動作鏈評估所有適用的暫時規則。

如需提供工作階段 ID、工作階段生命週期以及身分如何跨多躍點呼叫傳播的詳細資訊,請參閱政策工作階段和身分傳播。

政策評估

Cedar 評估:

  1. 委託人檢查:委託人是否為 OAuthUser? ✓ (相符)

  2. 動作檢查:動作 RefundTool___process_refund 是否? ✓ (相符)

  3. 資源檢查:資源是否為退款閘道? ✓ (相符)

  4. 條件檢查:

    • 主體是否有使用者名稱標籤? ✓ (是,來自 JWT)

    • username = "refund-agent" 嗎? ✓ (是)

    • context.input.amount 是否 < 500? ✓ (450 < 500)

結果:允許 - 所有檢查都通過,退款已獲得授權。