Livoa LogoLivoa
Client
Cognito User Pools


IN, US, UG Regions

dbRegion attribute

API Gateway


Authorizer & IAM Policies

Authorizer
Lambda
Region & Token Details


- dbRegion attribute assigned at registration (IN, US, UG)

- Region detection via IP for routing only

- Authentication against home region Cognito pool

- Tokens include dbRegion, role, access_type

- API Gateway validates tokens with region-specific keys

- Requests with mismatched dbRegion rejected

Special Scenarios


- India user logging in from US: Auth & backend in India only

- Indian admin traveling internationally: VPN required for access

- Uganda users mapped to US pool and backend

- Cross-region login attempts denied and logged

test

by rj

0
0 uses