Ultimate access to all questions.
A company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB), which serves as the origin for an Amazon CloudFront distribution. The company aims to implement a custom authentication system to issue tokens for authenticated customers. The web application must verify that GET/POST requests originate from authenticated customers before serving content.
What is the MOST operationally efficient solution that allows the web application to identify authorized customers?