Settings

Theme

Amazon S3: How can I secure uploads from a public page?

2 points by pankyj 7 years ago · 1 comment · 1 min read


I have heard about buckets being open to the public and hacked. As a developer, I am building a public facing website where anyone can upload photos. I am using something called 'Identity pool' with access to unauthenticated identities.

I got a CognitoIdentityCredentials which I use to upload photos via js to the bucket. My bucket has origins set to my website domain and allows all requests for this. The images uploaded to this bucket are ACL: 'public-read'.

Is this configuration secure? If not, in what way can someone with malicious intent break my bucket / website or steal my bucket data.

pankyjOP 7 years ago

Anyone?

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection