Empresas
Empregos
  • Sobre nós
  • Soluções
    • Publicação de vagas
      Publique sua vaga e receba candidatos qualificados em 48h.
    • Avaliações de candidatos
      Mais de 500 testes técnicos e psicológicos, mais anti-fraude.
    • Headhunting
      Busca executiva personalizada do início ao fim.
    • Folha de Pagamento + EOR
      Dispersão de folha e EOR em mais de 15 países da LATAM.
  • Preços
  • Empregos

0

124
Visualizações
s3 minimum upload bucket policy authorization

I'm trying to get a basic upload bucket to work, but I'm having trouble trying to wrap my head around the bucket policy needed.

I currently have:

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "AddPerm",
            "Effect": "Allow",
            "Principal": "*",
            "Action": "s3:*",
            "Resource": "arn:aws:s3:::waydope-development/*",
            "Condition": {
                "StringEquals": {
                    "s3:x-amz-acl": "public-read"
                }
            }
        }
    ]
}

The CORS are set to allow all. I can upload to this bucket by only supplying a key, but will this bucket if supplied with authorization, signature, and policy, return a 403 due to the fact that it is open? In other words, can I supply those keys without having the principal point at a user?

over 4 years ago · Santiago Trujillo
1 Respostas
Responde à pergunta

0

To see how a bucket policy relates to signing here is a question related to that: s3 how is the signature calculated

This is the minimum bucket policy where anyone can get, post, put, and delete an item in a bucket. All that is required in the formdata is the key - ie, file path.

Bucket Config:

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "AddPerm",
            "Effect": "Allow",
            "Principal": "*"
            "Action": "s3:*",
            "Resource": "arn:aws:s3:::example-development/*"
        }
    ]
}

This is the minimum bucket policy where user/group authentication is required for anything besides get for the bucket upload.

Bucket Config:

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "Allow Get",
            "Effect": "Allow",
            "Principal": "*",
            "Action": "s3:GetObject",
            "Resource": "arn:aws:s3:::example-development/*"
        },
        {
            "Sid": "AddPerm",
            "Effect": "Allow",
            "Principal": {
                "AWS": "arn:aws:iam::123456789:user/example"
            },
            "Action": "s3:*",
            "Resource": ["arn:aws:s3:::example-development/*","arn:aws:s3:::example-development"]
        }
    ]
}
over 4 years ago · Santiago Trujillo Relatório
Responde à pergunta
Encontrar trabalhos remotos

Descubra a nova forma de encontrar um emprego!

melhores empregos
Principais categorias de trabalho
Empresas
Postar vaga Preços Comercial
Jurídico
Termos e Condições Política de privacidade
© 2026 PeakU Inc. All Rights Reserved.
Andres GPT
Recomende algumas ofertas para mim
Preciso de ajuda