Skip to content

WAF and permission fixes #103

@EreminAnton

Description

@EreminAnton
  • ThrottlingBurstLimit &ThrottlingRateLimit configuration

WAF & Timeout

2. WAF , but make it optional and enabled by default . Who wants can remove it and use other solutions
3. https://1111111111.execute-api.eu-central-1.amazonaws.com/default/access-requester 20s timeout in case of empty POST request

IAM permissions review for SSO Elevator lamdas

'iam:Pass*', + "*" = Bad 
 'iam:AttachRolePolicy',
        'iam:PutRolePolicy',
        'iam:GetRole',
        'iam:CreateRole',
        'iam:ListRolePolicies',
        'iam:ListAttachedRolePolicies',

      'arn:aws:iam::*:role/aws-reserved/sso.amazonaws.com/*/AWSReservedSSO_*',
        'arn:aws:iam::*:role/aws-reserved/sso.amazonaws.com/AWSReservedSSO_*',
Are we creating roles/policy?

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

Projects

Status

In Progress

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions