AWS AmazonCloudWatch: Use ArnLike instead of StringLike in destination policy example
Summary
Updates the destination IAM policy example so the aws:SourceArn condition uses the ArnLike operator instead of StringLike.
Security assessment
Switching the aws:SourceArn condition from StringLike to ArnLike makes the sample policy's cross-account authorization check ARN-aware rather than a loose string match, reducing the chance that unintended source ARNs satisfy the condition. This is an IAM authorization hardening in documentation; no specific CVE or incident is cited.
Evidence
+ "ArnLike": {
Diff
diff --git a/AmazonCloudWatch/latest/logs/CreateDestination.md b/AmazonCloudWatch/latest/logs/CreateDestination.md index b13b3b9ab..8a43ab519 100644 --- a//AmazonCloudWatch/latest/logs/CreateDestination.md +++ b//AmazonCloudWatch/latest/logs/CreateDestination.md @@ -61 +61 @@ This policy includes a `aws:SourceArn` global condition context key that specifi - "StringLike": { + "ArnLike": {