mapbox / mapbox/magic-cfn-resources
Scope down permission on S3InventoryPolicy
Open
Nobody has claimed this yet.
enhancement
- Dominant language
- JavaScript
- Stars
- 6
- Forks
- 4
- PR merge metrics
- No merged PRs in 30d
Description
The [S3inventorypolicy](https://github.com/mapbox/magic-cfn-resources/blob/e655729b2e6dd9aa77f8e66abc6945c44cccac15/lib/build.js#L365-L400) has `Resource: *` permissions for s3.
These should be scoped down to the specific bucket, if possible.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start in lib/build.js around lines 365-400 and inspect how S3InventoryPolicy is assembled. Trace the bucket information available to that policy, then verify the generated permission uses the specific bucket rather than Resource: * where possible; confirm the resulting CloudFormation resource remains valid.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, javascript
- Domain
- cloud, security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100