S3权限错误对象锁定配置,同时只需单击桶内对象的复选框

MD.*_*hin 4 amazon-s3 amazon-web-services amazon-iam

我向集团授予以下许可。

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "VisualEditor0",
            "Effect": "Allow",
            "Action": [
                "s3:GetObject",
                "s3:ListBucket",
                "s3:DeleteBucket"
            ],
            "Resource": [
                "arn:aws:s3:::commonbuckettest/*",
                "arn:aws:s3:::commonbuckettest"
            ]
        },
        {
            "Sid": "VisualEditor1",
            "Effect": "Allow",
            "Action": "s3:ListAllMyBuckets",
            "Resource": "*"
        }
    ]
}
Run Code Online (Sandbox Code Playgroud)

这是自定义生成的策略。在该组中我有两个用户。使用一个用户登录并转到相应的存储桶和 sson 后,就像刚刚单击 chekbox 到一个对象一样,它会出现以下错误:

在此输入图像描述

Mar*_*cin 5

这不是一个错误。您不允许用户访问策略中的对象锁定信息,因此无法显示该信息。如果您希望用户查看对象锁定信息,您可以将其添加到您的策略中。例如:

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "VisualEditor0",
            "Effect": "Allow",
            "Action": [
                "s3:GetObject",
                "s3:ListBucket",
                "s3:DeleteBucket"
            ],
            "Resource": [
                "arn:aws:s3:::commonbuckettest/*",
                "arn:aws:s3:::commonbuckettest"
            ]
        },
        {
            "Sid": "AllowObjectLockConfiguration",
            "Effect": "Allow",
            "Action": "s3:GetBucketObjectLockConfiguration",
            "Resource": "*"
        },
        {
            "Sid": "VisualEditor1",
            "Effect": "Allow",
            "Action": "s3:ListAllMyBuckets",
            "Resource": "*"
        }
    ]
}
Run Code Online (Sandbox Code Playgroud)