Checking for a notice
node-cdn-url-auth-cdk.svrlss.advancelocal.dev
node-cdn-url-auth-cdk
Two sites from one AWS CDK stack in TypeScript: a public page that shows a site notice, and an admin site at admin.<hostname> where invited people sign in with Cognito, by email code or Entra, to set it. Saving writes the notice to the table and to a notice.json that CloudFront caches for 30 seconds and that other sites may read through CORS. The admin function keeps the session in an HttpOnly cookie, so the browser never holds a token.
App
- Node.js handlers
- Admin page in plain HTML and JavaScript
Runs on
- CloudFront, one distribution per site
- origin access control for S3 and Lambda
- response headers policies, with CORS on notice.json
- S3
- Lambda function URLs, IAM auth, Node.js, deployed with CDK
- Cognito user pool
- managed login
- email codes
- Entra federation
- DynamoDB
Foundation
- inf-baseline
- Wiz scanning
- Scheduled deploys and checks