fix(s3): publicReadAccess causes deployment failure due to access denied 403#29632
Merged
mergify[bot] merged 5 commits intomainfrom May 28, 2024
Merged
fix(s3): publicReadAccess causes deployment failure due to access denied 403#29632mergify[bot] merged 5 commits intomainfrom
mergify[bot] merged 5 commits intomainfrom
Conversation
TheRealAmazonKendra
previously requested changes
Mar 28, 2024
This was referenced Apr 1, 2024
Co-authored-by: Aayush thapa <84202325+aaythapa@users.noreply.github.com>
aaythapa
approved these changes
May 28, 2024
Contributor
|
Thank you for contributing! Your pull request will be updated from main and then merged automatically (do not update manually, and be sure to allow changes to be pushed to your fork). |
Collaborator
AWS CodeBuild CI Report
Powered by github-codebuild-logs, available on the AWS Serverless Application Repository |
Contributor
|
Thank you for contributing! Your pull request will be updated from main and then merged automatically (do not update manually, and be sure to allow changes to be pushed to your fork). |
rj-au
reviewed
Jun 3, 2024
|
|
||
| if (props.publicReadAccess) { | ||
| if (props.blockPublicAccess === undefined) { | ||
| throw new Error('Cannot use \'publicReadAccess\' property on a bucket without allowing bucket-level public access through \'blockPublicAceess\' property.'); |
There was a problem hiding this comment.
@GavinZZ
typo: blockPublicAceess -> blockPublicAccess (Aceess has 'ee' and missing a 'c')
vdahlberg
pushed a commit
to vdahlberg/aws-cdk
that referenced
this pull request
Jun 10, 2024
…ied 403 (aws#29632) ### Issue # (if applicable) Closes aws#29564 ### Reason for this change if you make a new s3 bucket ``` const staticBucket = new aws_s3.Bucket(s3Stack, `static-Bucket`, { bucketName: `static-bucket`, publicReadAccess: true, }) ``` While this is fine code and you can deploy it will fail in the middle with a generic access denied error not telling you what stopped it even if you are full admin. This happens due to the default deny all public access rule. ### Description of changes When users only enable `publicReadAccess` without configuring `blockPublicAccess` to disable it, we will raise an exception and throw an more appropriate error message for easier diagnosis. We do not want to directly disable `blockPublicAccess` as it feels like a weird behaviour. ### Description of how you validated changes New unit tests and updated integ tests ### Checklist - [x] My code adheres to the [CONTRIBUTING GUIDE](https://github.com/aws/aws-cdk/blob/main/CONTRIBUTING.md) and [DESIGN GUIDELINES](https://github.com/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md) ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
This was referenced Jun 29, 2024
This was referenced Jul 12, 2024
This was referenced Jul 19, 2024
Collaborator
|
Comments on closed issues and PRs are hard for our team to see. If you need help, please open a new issue that references this one. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Issue # (if applicable)
Closes #29564
Reason for this change
if you make a new s3 bucket
While this is fine code and you can deploy it will fail in the middle with a generic access denied error not telling you what stopped it even if you are full admin. This happens due to the default deny all public access rule.
Description of changes
When users only enable
publicReadAccesswithout configuringblockPublicAccessto disable it, we will raise an exception and throw an more appropriate error message for easier diagnosis.We do not want to directly disable
blockPublicAccessas it feels like a weird behaviour.Description of how you validated changes
New unit tests and updated integ tests
Checklist
By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license