From b83a77d38bccf8505bbba68cdf0ba3fec9cc9c7d Mon Sep 17 00:00:00 2001 From: Anthony Lukach Date: Thu, 24 Sep 2026 07:40:08 -0700 Subject: [PATCH] policies: stop granting s3:PutObjectAcl Uploads no longer need --acl bucket-owner-full-control, so the identity and bucket policies have no use for PutObjectAcl. Co-Authored-By: Claude Opus 5.5 (1M context) --- docs/using-source/data-upload.md | 1 - src/policies.check.ts | 1 + src/policies.ts | 1 - 3 files changed, 1 insertion(+), 2 deletions(-) diff --git a/docs/using-source/data-upload.md b/docs/using-source/data-upload.md index bd30ff1..bf468e3 100644 --- a/docs/using-source/data-upload.md +++ b/docs/using-source/data-upload.md @@ -256,7 +256,6 @@ The [IAM policy wizard](/tools/iam-policy-wizard) generates this policy for you "s3:PutObject", "s3:GetObject", "s3:DeleteObject", - "s3:PutObjectAcl", "s3:AbortMultipartUpload", "s3:ListMultipartUploadParts" ], diff --git a/src/policies.check.ts b/src/policies.check.ts index d88a404..9429bea 100644 --- a/src/policies.check.ts +++ b/src/policies.check.ts @@ -31,6 +31,7 @@ for (const bad of ['123456789012', 'arn:aws:s3:::bucket', 'arn:aws:iam::12345:ro const identity = buildIdentityPolicy(DEFAULT_BUCKET, 'org/product'); assert.equal(identity.Statement[0].Resource, `arn:aws:s3:::${DEFAULT_BUCKET}/org/product/*`); assert.ok(identity.Statement[0].Action.includes('s3:AbortMultipartUpload')); +assert.ok(!identity.Statement[0].Action.includes('s3:PutObjectAcl')); // s3:ListBucketMultipartUploads cannot be scoped to a prefix, so it must never // appear: it would expose every other provider's in-progress uploads. const grantsBucketWideMultipart = (policy) => diff --git a/src/policies.ts b/src/policies.ts index 82b78f7..1d0e374 100644 --- a/src/policies.ts +++ b/src/policies.ts @@ -61,7 +61,6 @@ const OBJECT_ACTIONS = [ 's3:PutObject', 's3:GetObject', 's3:DeleteObject', - 's3:PutObjectAcl', 's3:AbortMultipartUpload', 's3:ListMultipartUploadParts', ];