mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 15:03:16 +00:00
The prior fix scoped secretsmanager:BatchGetSecretValue to the env-prefixed secret ARN, but the live box still got AccessDenied: batch-get-secret-value invoked WITH a name --filters is a COLLECTION call that AWS authorizes against * (a per-secret ARN does not satisfy it). Split the statement: - GetSecretValue + DescribeSecret stay PREFIX-scoped (secret:open-swe-<env>/*) — this is what gates which secret VALUES the box can read (checked per-secret in the batch). - BatchGetSecretValue + ListSecrets move to a * operation-level statement (the filtered collection call + the list action; neither is resource-scopable for this usage). VALUE isolation preserved (dev box still cannot read prod secret values); only secret NAME/metadata enumeration is widened. GPT-4.1 IAM cross-review: BLOCK none, FIX none. Suppression OSWE-IAC-SECRETS-LIST-01 updated; future hardening (explicit --secret-id-list to drop both * grants) tracked there. |
||
|---|---|---|
| .. | ||
| aspects | ||
| constructs | ||
| config.ts | ||
| open-swe-iam-stack.ts | ||
| open-swe-stack.ts | ||