Description
An Azure file share’s stored access policy defines permissions for SAS tokens that reference it. rwdl combines file read, write, delete, and listing permissions.
Potential impact
A leaked or misused token can expose, modify, or delete files beyond the intended scope.
Remediation
Keep only permissions required for the task; use r for read-only access. Limit the policy’s validity period to the required interval.
Examples
The examples narrow access to read-only. Supply valid UTC start and expiry inputs, with expiry later than start.
Before
hcl
resource "azurerm_storage_share_file" "example" {
name = "my-awesome-content.zip"
storage_share_id = azurerm_storage_share.example.id
source = "some-local-file.zip"
}
resource "azurerm_storage_share" "example" {
name = "sharename"
storage_account_id = azurerm_storage_account.example.id
quota = 50
acl {
id = "MTIzNDU2Nzg5MDEyMzQ1Njc4OTAxMjM0NTY3ODkwMTI"
access_policy {
permissions = "rwdl"
start = var.policy_start_utc
expiry = var.policy_expiry_utc
}
}
}
After
hcl
resource "azurerm_storage_share_file" "example" {
name = "my-awesome-content.zip"
storage_share_id = azurerm_storage_share.example.id
source = "some-local-file.zip"
}
resource "azurerm_storage_share" "example" {
name = "sharename"
storage_account_id = azurerm_storage_account.example.id
quota = 50
acl {
id = "MTIzNDU2Nzg5MDEyMzQ1Njc4OTAxMjM0NTY3ODkwMTI"
access_policy {
permissions = "r"
start = var.policy_start_utc
expiry = var.policy_expiry_utc
}
}
}