Skip to content

Commit d58596b

Browse files
committed
split decrypt oracle Deny statement to deny invalid action OR invalid resource
1 parent d7e2a7d commit d58596b

File tree

1 file changed

+4
-1
lines changed

1 file changed

+4
-1
lines changed

decrypt_oracle/.chalice/policy-dev.json

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,10 @@
3434
"logs:CreateLogGroup",
3535
"logs:CreateLogStream",
3636
"logs:PutLogEvents"
37-
],
37+
]
38+
},
39+
{
40+
"Effect": "Deny",
3841
"NotResource": [
3942
"arn:aws:kms:us-west-2:658956600833:key/590fd781-ddde-4036-abec-3e1ab5a5d2ad",
4043
"arn:aws:kms:us-west-2:658956600833:key/b3537ef1-d8dc-4780-9f5a-55776cbb2f7f",

0 commit comments

Comments
 (0)