Description
In CloudFormation’s Alexa::ASK::Skill, AuthenticationConfiguration.RefreshToken is a secret used for Login with Amazon authentication. Writing it directly in a template leaves the token in code and repository history.
Potential impact
A leaked refresh token, together with the required client credentials, can be exchanged for new access tokens within its granted scope and used to misuse skill-management permissions.
Remediation
Store the issued refresh token and ClientSecret in Secrets Manager and pass them through dynamic references. Revoke and reissue exposed credentials, then update the deployment configuration. Changing a secret alone does not automatically refresh the CloudFormation resource.
Examples
Supply an existing skill package in S3 and a role ARN that allows it to be read. The alexa-auth secret contains clientSecret and refreshToken for the relevant Login with Amazon profile. Use the client and vendor IDs linked to the developer account. The original token is illustrative.
Before
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
ClientId:
Type: String
VendorId:
Type: String
SkillBucket:
Type: String
SkillKey:
Type: String
SkillBucketRoleArn:
Type: String
Resources:
MySkill:
Type: Alexa::ASK::Skill
Properties:
AuthenticationConfiguration:
ClientId: !Ref ClientId
ClientSecret: '{{resolve:secretsmanager:alexa-auth:SecretString:clientSecret}}'
RefreshToken: 'Atzr|1234'
VendorId: !Ref VendorId
SkillPackage:
S3Bucket: !Ref SkillBucket
S3Key: !Ref SkillKey
S3BucketRole: !Ref SkillBucketRoleArn
After
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
ClientId:
Type: String
VendorId:
Type: String
SkillBucket:
Type: String
SkillKey:
Type: String
SkillBucketRoleArn:
Type: String
Resources:
MySkill:
Type: Alexa::ASK::Skill
Properties:
AuthenticationConfiguration:
ClientId: !Ref ClientId
ClientSecret: '{{resolve:secretsmanager:alexa-auth:SecretString:clientSecret}}'
RefreshToken: '{{resolve:secretsmanager:alexa-auth:SecretString:refreshToken}}'
VendorId: !Ref VendorId
SkillPackage:
S3Bucket: !Ref SkillBucket
S3Key: !Ref SkillKey
S3BucketRole: !Ref SkillBucketRoleArn