Plaintext Alexa ASK skill refresh token

Keep Alexa ASK skill refresh tokens out of templates.

Description

In CloudFormation’s Alexa::ASK::Skill, AuthenticationConfiguration.RefreshToken is a secret used for Login with Amazon authentication. Writing it directly in a template leaves the token in code and repository history.

Potential impact

A leaked refresh token, together with the required client credentials, can be exchanged for new access tokens within its granted scope and used to misuse skill-management permissions.

Remediation

Store the issued refresh token and ClientSecret in Secrets Manager and pass them through dynamic references. Revoke and reissue exposed credentials, then update the deployment configuration. Changing a secret alone does not automatically refresh the CloudFormation resource.

Examples

Supply an existing skill package in S3 and a role ARN that allows it to be read. The alexa-auth secret contains clientSecret and refreshToken for the relevant Login with Amazon profile. Use the client and vendor IDs linked to the developer account. The original token is illustrative.

Before

yaml
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
  ClientId:
    Type: String
  VendorId:
    Type: String
  SkillBucket:
    Type: String
  SkillKey:
    Type: String
  SkillBucketRoleArn:
    Type: String
Resources:
  MySkill:
    Type: Alexa::ASK::Skill
    Properties:
      AuthenticationConfiguration:
        ClientId: !Ref ClientId
        ClientSecret: '{{resolve:secretsmanager:alexa-auth:SecretString:clientSecret}}'
        RefreshToken: 'Atzr|1234'
      VendorId: !Ref VendorId
      SkillPackage:
        S3Bucket: !Ref SkillBucket
        S3Key: !Ref SkillKey
        S3BucketRole: !Ref SkillBucketRoleArn

After

yaml
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
  ClientId:
    Type: String
  VendorId:
    Type: String
  SkillBucket:
    Type: String
  SkillKey:
    Type: String
  SkillBucketRoleArn:
    Type: String
Resources:
  MySkill:
    Type: Alexa::ASK::Skill
    Properties:
      AuthenticationConfiguration:
        ClientId: !Ref ClientId
        ClientSecret: '{{resolve:secretsmanager:alexa-auth:SecretString:clientSecret}}'
        RefreshToken: '{{resolve:secretsmanager:alexa-auth:SecretString:refreshToken}}'
      VendorId: !Ref VendorId
      SkillPackage:
        S3Bucket: !Ref SkillBucket
        S3Key: !Ref SkillKey
        S3BucketRole: !Ref SkillBucketRoleArn

References