From 1728f6e408f3eea88eb8af9c513513932771fea3 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Fri, 7 Aug 2026 19:21:45 -0400 Subject: [PATCH] fix(iam): scope SES SendRawEmail to verified identities Constrain the email-report role to the sender and domain identity ARNs so the policy is not unconstrained write. --- terraform/iam.tf | 16 +++++++++------- 1 file changed, 9 insertions(+), 7 deletions(-) diff --git a/terraform/iam.tf b/terraform/iam.tf index 95dc6f1..d24f647 100644 --- a/terraform/iam.tf +++ b/terraform/iam.tf @@ -388,14 +388,16 @@ data "aws_iam_policy_document" "email_report" { resources = [aws_s3_bucket.reports.arn] } - # SES does not support resource-level permissions for SendRawEmail; the - # sender identity is enforced by SES verification, not IAM. Matches - # template.yaml. + # Scope SendRawEmail to the verified sender domain/identity rather than "*". + # SES still enforces verification; IAM pins the From identity ARNs. statement { - sid = "SendPayrollReport" - effect = "Allow" - actions = ["ses:SendRawEmail"] - resources = ["*"] + sid = "SendPayrollReport" + effect = "Allow" + actions = ["ses:SendRawEmail"] + resources = [ + "arn:aws:ses:${var.aws_region}:${local.account_id}:identity/${var.sender_email}", + "arn:aws:ses:${var.aws_region}:${local.account_id}:identity/seahavenind.com", + ] } }