Description
Writing BasicAuthConfig.Password directly in a CloudFormation AWS::Amplify::App, or in a parameter Default, leaves the app’s password in code and history.
Potential impact
An exposed username and password can grant access to a site protected by Basic Auth. Other environments that reuse the password may also be affected.
Remediation
Reference the password from Secrets Manager and keep it out of parameter defaults. Replace an exposed password. Changing the secret alone does not refresh the Amplify configuration; update the affected resource to apply the new value.
Examples
RepositoryUrl is the GitHub repository URL, and GitHubTokenSecretId identifies a secret containing a real GitHub token under the token key. The revised template generates a separate Basic Auth password. The password in the original example is illustrative.
Before
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
RepositoryUrl:
Type: String
GitHubTokenSecretId:
Type: String
Resources:
NewAmpApp1:
Type: AWS::Amplify::App
Properties:
Name: NewAmpApp
Repository: !Ref RepositoryUrl
AccessToken: !Sub '{{resolve:secretsmanager:${GitHubTokenSecretId}:SecretString:token}}'
BasicAuthConfig:
EnableBasicAuth: true
Password: "@skdsjdk0234!AB"
Username: admin
After
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
RepositoryUrl:
Type: String
GitHubTokenSecretId:
Type: String
Resources:
NewAmpApp1:
Type: AWS::Amplify::App
Properties:
Name: NewAmpApp
Repository: !Ref RepositoryUrl
AccessToken: !Sub '{{resolve:secretsmanager:${GitHubTokenSecretId}:SecretString:token}}'
BasicAuthConfig:
EnableBasicAuth: true
Password: !Sub '{{resolve:secretsmanager:${MyAmpAppSecretManagerRotater}:SecretString:password}}'
Username: !Sub '{{resolve:secretsmanager:${MyAmpAppSecretManagerRotater}:SecretString:username}}'
MyAmpAppSecretManagerRotater:
Type: AWS::SecretsManager::Secret
Properties:
GenerateSecretString:
SecretStringTemplate: '{"username": "admin"}'
GenerateStringKey: password
PasswordLength: 16