AWS appstream2: Add confused deputy prevention conditions to S3 bucket policies
Summary
Updates example S3 bucket policies to add aws:SourceAccount conditions for confused deputy prevention and splits out a separate statement granting appstream.amazonaws.com GetObject access to application icons, noting icons don't support confused deputy prevention.
Security assessment
The change adds aws:SourceAccount condition keys to the cross-service S3 bucket policy statements, which is the documented mechanism for cross-service confused deputy prevention, tightening IAM trust so only the intended account's service calls are honored.
Evidence
"aws:SourceAccount": "111122223333"
Diff
diff --git a/appstream2/latest/developerguide/s3-permissions.md b/appstream2/latest/developerguide/s3-permissions.md index 1db8fa3..1910de1 100644 --- a//appstream2/latest/developerguide/s3-permissions.md +++ b//appstream2/latest/developerguide/s3-permissions.md @@ -15,4 +15 @@ This section presents examples of typical use cases for bucket policies. These s -JSON - - -**** +###### Note @@ -19,0 +17 @@ JSON +WorkSpaces Applications doesn't support confused deputy prevention for application icons, so the statement that grants access to the application icon object can't include a condition. For more information, see [Example: WorkSpaces Applications Application Amazon S3 bucket policy cross-service confused deputy prevention](./example-s3-bucket.html). @@ -26 +24 @@ JSON - "Sid": "AllowAppStream2.0ToRetrieveObjects", + "Sid": "AllowAppStream20ToRetrieveObjects", @@ -35 +32,0 @@ JSON - "arn:aws:s3:::bucket/Application icon object", @@ -37 +34,15 @@ JSON - ] + ], + "Condition": { + "StringEquals": { + "aws:SourceAccount": "111122223333" + } + } + }, + { + "Sid": "AllowRetrievalPermissionsToS3AppIconsForAppStream", + "Effect": "Allow", + "Principal": { + "Service": ["appstream.amazonaws.com"] + }, + "Action": ["s3:GetObject"], + "Resource": "arn:aws:s3:::bucket/Application icon object" @@ -49,6 +58,0 @@ If you are using an WorkSpaces Applications app block, then WorkSpaces Applicati -JSON - - -**** - - @@ -60 +64 @@ JSON - "Sid": "AllowAppStream2.0ToPutAndRetrieveObjects", + "Sid": "AllowAppStream20ToPutAndRetrieveObjects", @@ -77 +80,0 @@ JSON - "arn:aws:s3:::bucket/Application icon object", @@ -78,0 +82,13 @@ JSON + ], + "Condition": { + "StringEquals": { + "aws:SourceAccount": "111122223333" + } + } + }, + { + "Sid": "AllowRetrievalPermissionsToS3AppIconsForAppStream", + "Effect": "Allow", + "Principal": { + "Service": [ + "appstream.amazonaws.com" @@ -79,0 +96,5 @@ JSON + }, + "Action": [ + "s3:GetObject" + ], + "Resource": "arn:aws:s3:::bucket/Application icon object"