--policy or --statement implies --user-permissions-boundary none, refs #74

pull/84/head
Simon Willison 2022-08-01 12:31:56 -07:00
rodzic db90d36ddc
commit 9926a98b16
2 zmienionych plików z 4 dodań i 1 usunięć

Wyświetl plik

@ -328,6 +328,9 @@ def create(
if write_only:
permission = "write-only"
if not user_permissions_boundary and (policy or extra_statements):
user_permissions_boundary = "none"
s3 = None
iam = None
sts = None

Wyświetl plik

@ -68,7 +68,7 @@ Would call create access key for user 's3.read-write.my-bucket'"""
],
(
"""Would create bucket: 'my-bucket'
Would create user: 's3.custom.my-bucket' with permissions boundary: 'arn:aws:iam::aws:policy/AmazonS3FullAccess'
Would create user: 's3.custom.my-bucket'
*"Action": "textract:*"""
),
),