AWS notifications: Fix managed notification ARN format in IAM policy example
Summary
Corrected ARN syntax in managed notification policy example and minor wording improvements
Security assessment
The ARN correction ensures policy examples are syntactically valid, preventing potential misconfiguration of resource permissions. While IAM-related, there's no evidence of a specific vulnerability being addressed.
Evidence
"Resource": "arn:aws:notifications::123456789012:managed-notification-configuration/category/AWS-Health/sub-category/*"
Diff
diff --git a/notifications/latest/userguide/resource-level-permissions.md b/notifications/latest/userguide/resource-level-permissions.md index 3572fde28..03b270d42 100644 --- a//notifications/latest/userguide/resource-level-permissions.md +++ b//notifications/latest/userguide/resource-level-permissions.md @@ -7 +7 @@ -Supported resource-level permissions for User Notifications API actionsExample 1: Full accessExample 2: ReadOnly accessExample 3: Deny a user the ability to update a notification configurationExample 4: Allow users to create notification configurations and associate emails to themExample 5: Allow users full create, read, update, and delete (CRUD) access.Example 6: Full read-write access with explicit actionsExample 7: Resource-scoped access for managed notifications +Supported resource-level permissions for User Notifications API actionsExample 1: Full accessExample 2: ReadOnly accessExample 3: Deny a user the ability to update a notification configurationExample 4: Allow users to create notification configurations and associate emails with themExample 5: Allow users full create, read, update, and delete accessExample 6: Full read-write access with explicit actionsExample 7: Resource-scoped access for managed notifications @@ -11 +11 @@ Supported resource-level permissions for User Notifications API actionsExample 1 - _Resource-level permissions_ define the AWS resources that you allow assigned entities (users, groups, and roles) to perform actions on. You specifiy the Amazon Resource Name (ARN) of one or more resources as part of an IAM policy. You can then attach this policy to IAM entities. When the action doesn't act on a named resource, or when you grant permission to perform the action on all resources, the value of the resource in the policy is a wildcard (*****). + _Resource-level permissions_ define the AWS resources that you allow assigned entities (users, groups, and roles) to perform actions on. You specify the Amazon Resource Name (ARN) of one or more resources as part of an IAM policy. You can then attach this policy to IAM entities. When the action doesn't act on a named resource or you grant permission to perform the action on all resources, the value for the resource in the policy is a wildcard (*****). @@ -66 +66 @@ UntagResource | `arn:aws:notifications-contacts::`accountId`:emailcontact/`emai -This policy allows a user to call all available APIs. +This policy allows a user to call all available API actions. @@ -92 +92 @@ JSON -This policy allows a user to use get and list API actions. +This policy allows a user to call all get and list API actions. @@ -144 +144 @@ JSON -## Example 4: Allow users to create notification configurations and associate emails to them +## Example 4: Allow users to create notification configurations and associate emails with them @@ -146 +146 @@ JSON -This policy allows users to create notification configurations and associate emails to those configurations. +This policy allows users to create notification configurations and associate emails with those configurations. @@ -176 +176 @@ JSON -## Example 5: Allow users full create, read, update, and delete (CRUD) access. +## Example 5: Allow users full create, read, update, and delete access @@ -178 +178 @@ JSON -This policy allows users full CRUD access. +This policy allows users full create, read, update, and delete (CRUD) access. @@ -281,6 +280,0 @@ This policy demonstrates least-privilege access by scoping managed notification -JSON - - -**** - - @@ -307 +301 @@ JSON - "Resource": "arn:aws::notifications::123456789012:managed-notification-configuration/category/AWS-Health/sub-category/*" + "Resource": "arn:aws:notifications::123456789012:managed-notification-configuration/category/AWS-Health/sub-category/*"