Description
Wildcard grants for both actions and principals in an OSS bucket policy can provide more access than needed. oss:* covers a broad set of actions, whereas a wildcard such as oss:Get* identifies a particular action family and does not itself grant writes or deletes. Review the actions together with their bucket and object paths.
Effective access depends on policy conditions, explicit denies, ACLs, and Block Public Access. acl = "private" alone does not block all policy-based access. In OSS, an empty Principal array also means all principals; do not use it to restrict access.
Potential impact
- Objects with effective public read permission may disclose their contents beyond the intended audience. An action such as
oss:Get*does not itself imply permission to write or delete. - If a wildcard action range includes writes or deletes and applies to the resource, principals that do not need those permissions may be able to change or delete data.
- Permission to change bucket settings can allow changes to access controls or other configuration. Check each operation's restrictions and resource scope.
Remediation
- Specify the required principals, actions, and bucket or object paths. Remove unnecessary wildcard grants, and do not include writes or administrative actions merely to support public reads.
- Review policy conditions, explicit denies, ACLs, and Block Public Access together. Verify permissions against valid policies and the actual request conditions.
- Inline
policyhas been deprecated since provider version 1.220.0. Manage new configurations withalicloud_oss_bucket_policy, and verify that required permissions remain intact when migrating an existing configuration.
Examples
These examples compare an allow statement with an explicit deny using the legacy inline policy form supported in provider 1.293.0. Choose an available, unique bucket name and update the policy's resource paths to match.
Broad action grant
resource "alicloud_oss_bucket" "bucket-policy1" {
bucket = "bucket-1-policy"
acl = "private"
policy = <<POLICY
{"Statement": [
{
"Action": [
"oss:*"
],
"Effect": "Allow",
"Principal": [
"*"
],
"Resource": [
"acs:oss:*:*:bucket-1-policy",
"acs:oss:*:*:bucket-1-policy/*"
]
}
],
"Version":"1"}
POLICY
}
This statement intends to grant oss:* on the bucket and its objects to all principals. Check Block Public Access and operation-specific restrictions, and grant only the actions and principals that are required.
Broad explicit deny
resource "alicloud_oss_bucket" "bucket-policy1" {
bucket = "bucket-1-policy"
acl = "private"
policy = <<POLICY
{"Statement": [
{
"Action": [
"oss:*"
],
"Effect": "Deny",
"Principal": [
"*"
],
"Resource": [
"acs:oss:*:*:bucket-1-policy",
"acs:oss:*:*:bucket-1-policy/*"
]
}
],
"Version":"1"}
POLICY
}
When this explicit deny applies, it can block required operations too. Remove or narrow unnecessary grants while preserving the access that authorized users need rather than applying this blanket deny unchanged.