Description
The OauthToken property of CloudFormation’s AWS::Amplify::App supplies credentials for a repository connection with a provider other than GitHub. A literal token or a parameter Default leaves the credential in the template and repository history.
Potential impact
Someone who obtains the token may access repositories or related resources within its permissions.
Remediation
Store a provider-issued token in Secrets Manager and pass it through a dynamic reference. Keep it out of parameter defaults, and revoke and replace an exposed token at the provider. Use AccessToken for new GitHub connections.
Examples
Supply the provider’s repository URL as RepositoryUrl. The revised template also takes the name or ARN of an existing secret containing the issued token under the token key. The example token is not a real credential; a randomly generated password cannot replace an OAuth token.
Before
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
RepositoryUrl:
Type: String
Resources:
NewAmpApp1:
Type: AWS::Amplify::App
Properties:
Name: NewAmpApp
Repository: !Ref RepositoryUrl
OauthToken: EXAMPLE_NOT_A_REAL_OAUTH_TOKEN
After
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
RepositoryUrl:
Type: String
MyAmpAppSecretManagerRotater:
Type: String
Resources:
NewAmpApp1:
Type: AWS::Amplify::App
Properties:
Name: NewAmpApp
Repository: !Ref RepositoryUrl
OauthToken: !Sub '{{resolve:secretsmanager:${MyAmpAppSecretManagerRotater}:SecretString:token}}'