Comments (3)
Hello, which lines are you seeing this stated otherwise? On the linked page I see the following:
"For anonymous users, these two methods are equivalent."
from amazon-s3-userguide.
Hi Alan
This part:
Because anyone can create an AWS account, the security level of these two methods is equivalent, even though they function differently.
In reality, you don't even need AWS account, tested with a browser in private mode and still worked,
The proper way of blocking this access to non-AWS users is to add a Condition:
"Condition": { "Null": { "aws:PrincipalArn": false}}
Edit: if you want to discuss this more internally my ID: mjkubba@
from amazon-s3-userguide.
Closing this issue or pull request in advance of archiving this repo. For more information about the decision to archive this repo (and others in the 'awsdocs' org), see the announcement on the AWS News Blog.
from amazon-s3-userguide.
Related Issues (16)
- No option available to create S3 specific cost and usage report HOT 1
- S3 CORS configs must now be in JSON - need to remove the XML example HOT 1
- S3 Client side encryption docs reference outdated info. HOT 1
- Announcements about S3 BitTorrent discontinuation shouldn't be buried in the commit history HOT 4
- Host Zone HOT 1
- S3 Event Notifications on object version/deletemarker delete HOT 1
- question about bucket inventory HOT 2
- Are upload limits in GB or GiB? HOT 2
- Role missing some authorization for replication HOT 1
- s3:TlsVersion condition example grants access to any (anonymous) users HOT 2
- SCP: BucketOwnerEnforced issue HOT 3
- Incorrect information regarding versioning on `Deleting multiple objects` HOT 2
- When to use "s3:x-amz-server-side-encryption" policy? HOT 1
- How to get users list who have access to s3 bucket HOT 3
- Callback for receiving notification on a bucket HOT 2
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from amazon-s3-userguide.