Exposed Amplify app OAuth token

Putting an Amplify app OAuth token in a template leaves repository credentials in code and history.

Description

The OauthToken property of CloudFormation’s AWS::Amplify::App supplies credentials for a repository connection with a provider other than GitHub. A literal token or a parameter Default leaves the credential in the template and repository history.

Potential impact

Someone who obtains the token may access repositories or related resources within its permissions.

Remediation

Store a provider-issued token in Secrets Manager and pass it through a dynamic reference. Keep it out of parameter defaults, and revoke and replace an exposed token at the provider. Use AccessToken for new GitHub connections.

Examples

Supply the provider’s repository URL as RepositoryUrl. The revised template also takes the name or ARN of an existing secret containing the issued token under the token key. The example token is not a real credential; a randomly generated password cannot replace an OAuth token.

Before

yaml
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
  RepositoryUrl:
    Type: String
Resources:
  NewAmpApp1:
    Type: AWS::Amplify::App
    Properties:
      Name: NewAmpApp
      Repository: !Ref RepositoryUrl
      OauthToken: EXAMPLE_NOT_A_REAL_OAUTH_TOKEN

After

yaml
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
  RepositoryUrl:
    Type: String
  MyAmpAppSecretManagerRotater:
    Type: String
Resources:
  NewAmpApp1:
    Type: AWS::Amplify::App
    Properties:
      Name: NewAmpApp
      Repository: !Ref RepositoryUrl
      OauthToken: !Sub '{{resolve:secretsmanager:${MyAmpAppSecretManagerRotater}:SecretString:token}}'

References