mirror of
https://github.com/Sea-Haven-Industries/meal-order-manager.git
synced 2026-09-30 06:33:12 +00:00
fix(iam): scope SES SendRawEmail to verified identities
Constrain the email-report role to the sender and domain identity ARNs so the policy is not unconstrained write.
This commit is contained in:
parent
40ea4ed898
commit
1728f6e408
1 changed files with 9 additions and 7 deletions
|
|
@ -388,14 +388,16 @@ data "aws_iam_policy_document" "email_report" {
|
|||
resources = [aws_s3_bucket.reports.arn]
|
||||
}
|
||||
|
||||
# SES does not support resource-level permissions for SendRawEmail; the
|
||||
# sender identity is enforced by SES verification, not IAM. Matches
|
||||
# template.yaml.
|
||||
# Scope SendRawEmail to the verified sender domain/identity rather than "*".
|
||||
# SES still enforces verification; IAM pins the From identity ARNs.
|
||||
statement {
|
||||
sid = "SendPayrollReport"
|
||||
effect = "Allow"
|
||||
actions = ["ses:SendRawEmail"]
|
||||
resources = ["*"]
|
||||
sid = "SendPayrollReport"
|
||||
effect = "Allow"
|
||||
actions = ["ses:SendRawEmail"]
|
||||
resources = [
|
||||
"arn:aws:ses:${var.aws_region}:${local.account_id}:identity/${var.sender_email}",
|
||||
"arn:aws:ses:${var.aws_region}:${local.account_id}:identity/seahavenind.com",
|
||||
]
|
||||
}
|
||||
}
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue