Exposed Amplify branch Basic Auth password

Putting an Amplify branch Basic Auth password in a template leaves branch credentials in code.

Description

Writing BasicAuthConfig.Password directly in a CloudFormation AWS::Amplify::Branch, or in a parameter Default, leaves the branch’s password in the template and history.

Potential impact

An exposed username and password can allow unauthorized access to the protected branch site. Other branches that reuse the password may also be affected.

Remediation

Reference the password from Secrets Manager and keep it out of parameter defaults. Replace an exposed password and update the Amplify branch resource to apply the new value. Changing the secret alone does not refresh the branch configuration.

Examples

Supply an existing app ID as AmplifyAppId and the target branch name as BranchName. The original password is illustrative. The revised template generates and references a separate Basic Auth password.

Before

yaml
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
  AmplifyAppId:
    Type: String
  BranchName:
    Type: String
Resources:
  NewAmpApp1:
    Type: AWS::Amplify::Branch
    Properties:
      AppId: !Ref AmplifyAppId
      BranchName: !Ref BranchName
      EnableAutoBuild: false
      EnablePerformanceMode: false
      EnablePullRequestPreview: false
      BasicAuthConfig:
        EnableBasicAuth: true
        Password: "@skdsjdk0234!AB"
        Username: admin

After

yaml
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
  AmplifyAppId:
    Type: String
  BranchName:
    Type: String
Resources:
  NewAmpApp1:
    Type: AWS::Amplify::Branch
    Properties:
      AppId: !Ref AmplifyAppId
      BranchName: !Ref BranchName
      EnableAutoBuild: false
      EnablePerformanceMode: false
      EnablePullRequestPreview: false
      BasicAuthConfig:
        EnableBasicAuth: true
        Password: !Sub '{{resolve:secretsmanager:${MyAmpAppSecretManagerRotater}:SecretString:password}}'
        Username: !Sub '{{resolve:secretsmanager:${MyAmpAppSecretManagerRotater}:SecretString:username}}'
  MyAmpAppSecretManagerRotater:
    Type: AWS::SecretsManager::Secret
    Properties:
      GenerateSecretString:
        SecretStringTemplate: '{"username": "admin"}'
        GenerateStringKey: password
        PasswordLength: 16

References