Exposed Amplify app Basic Auth password

A plaintext Amplify app Basic Auth password can expose credentials through the template.

Description

Writing BasicAuthConfig.Password directly in a CloudFormation AWS::Amplify::App, or in a parameter Default, leaves the app’s password in code and history.

Potential impact

An exposed username and password can grant access to a site protected by Basic Auth. Other environments that reuse the password may also be affected.

Remediation

Reference the password from Secrets Manager and keep it out of parameter defaults. Replace an exposed password. Changing the secret alone does not refresh the Amplify configuration; update the affected resource to apply the new value.

Examples

RepositoryUrl is the GitHub repository URL, and GitHubTokenSecretId identifies a secret containing a real GitHub token under the token key. The revised template generates a separate Basic Auth password. The password in the original example is illustrative.

Before

yaml
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
  RepositoryUrl:
    Type: String
  GitHubTokenSecretId:
    Type: String
Resources:
  NewAmpApp1:
    Type: AWS::Amplify::App
    Properties:
      Name: NewAmpApp
      Repository: !Ref RepositoryUrl
      AccessToken: !Sub '{{resolve:secretsmanager:${GitHubTokenSecretId}:SecretString:token}}'
      BasicAuthConfig:
        EnableBasicAuth: true
        Password: "@skdsjdk0234!AB"
        Username: admin

After

yaml
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
  RepositoryUrl:
    Type: String
  GitHubTokenSecretId:
    Type: String
Resources:
  NewAmpApp1:
    Type: AWS::Amplify::App
    Properties:
      Name: NewAmpApp
      Repository: !Ref RepositoryUrl
      AccessToken: !Sub '{{resolve:secretsmanager:${GitHubTokenSecretId}:SecretString:token}}'
      BasicAuthConfig:
        EnableBasicAuth: true
        Password: !Sub '{{resolve:secretsmanager:${MyAmpAppSecretManagerRotater}:SecretString:password}}'
        Username: !Sub '{{resolve:secretsmanager:${MyAmpAppSecretManagerRotater}:SecretString:username}}'
  MyAmpAppSecretManagerRotater:
    Type: AWS::SecretsManager::Secret
    Properties:
      GenerateSecretString:
        SecretStringTemplate: '{"username": "admin"}'
        GenerateStringKey: password
        PasswordLength: 16

References