Description
In an SNS topic policy, Principal: "*" does not limit access to a specific account or role. Granting actions more broadly than necessary without suitable conditions can let untrusted principals publish messages or perform other allowed operations. Effective access depends on the actions, topic, conditions, and other applicable policies.
An access-grant statement in a topic policy needs a valid Principal and Effect: Allow. Omitting the principal from an allow statement is not a valid way to restrict access, and the omission itself does not grant access either.
Account-related conditions have different meanings. aws:ResourceAccount identifies the target resource's owner; it does not restrict the caller's account. aws:SourceAccount constrains the source resource's account in supported AWS service-to-service requests, rather than restricting every caller's account generally.
Potential impact
- If
sns:Publishis effectively granted to principals that do not need it, unwanted messages can be published to the topic. - When subscribers or automation receive those messages, they may generate misleading alerts, processing errors, or additional costs.
- Effective cross-account permissions that exceed requirements can allow access beyond the intended trust boundary. The impact depends on actual actions, resources, and request conditions.
Remediation
- Specify required AWS accounts, roles, or services using valid
Principalsyntax, and remove unnecessary allow statements. - Specify only required actions, such as
sns:Publish, and exact topic ARNs. For service integrations, use conditions such asaws:SourceArnandaws:SourceAccountwhere the service supports them, and validate their operators and actual values. - Review the complete policy and associated
Topics, and test requests that should be allowed and requests that should be denied. Confirm that required publishers and service integrations continue to work.
Topic policy configuration examples
These excerpts compare principal specifications. Both omit the required Topics property and use the incomplete ARN arn:aws:sns:MyTopic, which has no Region or account ID. They are not templates ready for deployment.
Publishing grant to a wildcard principal
AWSTemplateFormatVersion: '2010-09-09'
Description: ''
Resources:
snsPolicy:
Type: AWS::SNS::TopicPolicy
Properties:
PolicyDocument:
Statement:
- Sid: MyTopicPolicy
Effect: Allow
Principal: "*"
Action:
- sns:Publish
Resource: arn:aws:sns:MyTopic
This statement intends to allow sns:Publish without limiting it to particular principals or conditions. When supplying the missing deployment properties, also restrict the grant to the required publishers and topic.
Incomplete principal specification
AWSTemplateFormatVersion: '2010-09-09'
Description: ''
Resources:
snsPolicy:
Type: AWS::SNS::TopicPolicy
Properties:
PolicyDocument:
Statement:
- Sid: MyTopicPolicy
Effect: Allow
Principal: "otherPrincipal"
Action:
- sns:Publish
Resource: arn:aws:sns:MyTopic
otherPrincipal is not a valid AWS account or role identity. Replace it with a valid principal specification for the intended account, role, or service, complete the topic ARN and Topics, and validate the entire policy.