Description
OSS supports both HTTP and HTTPS requests. Without an HTTPS-only policy, other permissions can allow plaintext requests.
Potential impact
Object data and request information sent over HTTP may be exposed or altered in transit.
Remediation
Explicitly deny requests with acs:SecureTransport set to false for the bucket and its objects. An Allow statement limited to HTTPS does not override HTTP access granted by other policies.
Examples
The examples change Allow to Deny for the same transport condition. Supply the bucket owner UID and name through variables, and merge the denial into the existing policy.
Before
hcl
resource "alicloud_oss_bucket" "bucket" {
bucket = var.bucket_name
policy = <<POLICY
{
"Version": "1",
"Statement": [
{
"Effect": "Allow",
"Principal": ["*"],
"Action": ["oss:*"],
"Resource": [
"acs:oss:*:${var.bucket_owner_uid}:${var.bucket_name}",
"acs:oss:*:${var.bucket_owner_uid}:${var.bucket_name}/*"
],
"Condition": {
"Bool": {
"acs:SecureTransport": ["false"]
}
}
}
]
}
POLICY
}
After
hcl
resource "alicloud_oss_bucket" "bucket" {
bucket = var.bucket_name
policy = <<POLICY
{
"Version": "1",
"Statement": [
{
"Effect": "Deny",
"Principal": ["*"],
"Action": ["oss:*"],
"Resource": [
"acs:oss:*:${var.bucket_owner_uid}:${var.bucket_name}",
"acs:oss:*:${var.bucket_owner_uid}:${var.bucket_name}/*"
],
"Condition": {
"Bool": {
"acs:SecureTransport": ["false"]
}
}
}
]
}
POLICY
}