【发布时间】:2020-12-18 12:34:11
【问题描述】:
我想创建一个 S3 存储桶策略,它可以阻止公共访问,但只允许通过 Cognito 注册我的应用程序的人能够通过应用程序上传对象。
我拥有的当前存储桶策略:
{
"Version": "2012-10-17",
"Id": "Policy1593320409523",
"Statement": [
{
"Sid": "Stmt1593320397284",
"Effect": "Allow",
"Principal": {
"AWS": [
"arn:aws:iam::358110801253:role/Cognito_katebUnauth_Role",
"arn:aws:iam::358110801253:role/service-role/transcribe-role-k5easa7b",
"arn:aws:iam::358110801253:role/Cognito_katebAuth_Role"
]
},
"Action": "s3:*",
"Resource": [
"arn:aws:s3:::va-raw-audio-to-transcribe/*",
"arn:aws:s3:::va-raw-audio-to-transcribe"
]
}
]
}
【问题讨论】:
标签: amazon-web-services amazon-s3