Alicloud OSS bucket does not require HTTPS

Deny unencrypted requests in the bucket policy.

Description

OSS supports both HTTP and HTTPS requests. Without an HTTPS-only policy, other permissions can allow plaintext requests.

Potential impact

Object data and request information sent over HTTP may be exposed or altered in transit.

Remediation

Explicitly deny requests with acs:SecureTransport set to false for the bucket and its objects. An Allow statement limited to HTTPS does not override HTTP access granted by other policies.

Examples

The examples change Allow to Deny for the same transport condition. Supply the bucket owner UID and name through variables, and merge the denial into the existing policy.

Before

hcl
resource "alicloud_oss_bucket" "bucket" {
  bucket = var.bucket_name
  policy = <<POLICY
{
  "Version": "1",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": ["*"],
      "Action": ["oss:*"],
      "Resource": [
        "acs:oss:*:${var.bucket_owner_uid}:${var.bucket_name}",
        "acs:oss:*:${var.bucket_owner_uid}:${var.bucket_name}/*"
      ],
      "Condition": {
        "Bool": {
          "acs:SecureTransport": ["false"]
        }
      }
    }
  ]
}
POLICY
}

After

hcl
resource "alicloud_oss_bucket" "bucket" {
  bucket = var.bucket_name
  policy = <<POLICY
{
  "Version": "1",
  "Statement": [
    {
      "Effect": "Deny",
      "Principal": ["*"],
      "Action": ["oss:*"],
      "Resource": [
        "acs:oss:*:${var.bucket_owner_uid}:${var.bucket_name}",
        "acs:oss:*:${var.bucket_owner_uid}:${var.bucket_name}/*"
      ],
      "Condition": {
        "Bool": {
          "acs:SecureTransport": ["false"]
        }
      }
    }
  ]
}
POLICY
}

References