{"_id":"@aws-mdaa/s3-bucketpolicy-helper","_rev":"6-dae678bff40ed71f5b61223e576060d5","name":"@aws-mdaa/s3-bucketpolicy-helper","dist-tags":{"latest":"1.7.0"},"versions":{"1.2.0":{"name":"@aws-mdaa/s3-bucketpolicy-helper","version":"1.2.0","author":{"url":"https://aws.amazon.com/solutions","name":"Amazon Web Services"},"license":"Apache-2.0","_id":"@aws-mdaa/s3-bucketpolicy-helper@1.2.0","maintainers":[{"name":"mdaa-dev-team","email":"mdaa-dev-team@amazon.com"}],"homepage":"https://github.com/aws/modern-data-architecture-accelerator#readme","bugs":{"url":"https://github.com/aws/modern-data-architecture-accelerator/issues"},"dist":{"shasum":"0a8bf9447b6001a45f208f4b7cd07a54e3b4df52","tarball":"https://registry.npmjs.org/@aws-mdaa/s3-bucketpolicy-helper/-/s3-bucketpolicy-helper-1.2.0.tgz","fileCount":4,"integrity":"sha512-nj1rWYtV9Bmk3m4Y+5i/EOvtuWLq+OQykdWjkZAi2+LqIBy5Ux8CrA7ORrHs0eY0mrg7ddf9OTzNtSGvOsnExw==","signatures":[{"sig":"MEUCIQCAlQL5g+GPLji6dV5sYXz884ReM8ZKgQkL2x+8u0Z6xAIga9axmGr0dtx3GqG4i3Hq7L/9RgM5BNeklTuIr+IGgUk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":41154},"main":"lib/index.js","types":"lib/index.d.ts","gitHead":"8b49a2b371014baec046605ffdbfe38951099c31","scripts":{"lint":"eslint --max-warnings 0 -c ../../../.eslintrc.json '**/*.{ts,tsx}' --ignore-pattern 'dist/*' --ignore-pattern 'node_modules/*' --ignore-pattern \"*.d.ts\" ","test":"jest --passWithNoTests --coverage","build":"tsc","watch":"tsc -w","test-coverage":"jest --passWithNoTests --coverage"},"_npmUser":{"name":"mdaa-dev-team","email":"mdaa-dev-team@amazon.com"},"overrides":{"aws-cdk-lib":"2.201.0","@types/babel__traverse":"7.18.2"},"repository":{"url":"git+https://github.com/aws/modern-data-architecture-accelerator.git","type":"git"},"_npmVersion":"10.9.3","description":"MDAA s3-bucketpolicy-helper utility","directories":{},"_nodeVersion":"22.20.0","dependencies":{"cdk-nag":"2.37.1","constructs":"10.0.96","aws-cdk-lib":"2.201.0","@aws-mdaa/naming":"1.2.0","@aws-mdaa/iam-role-helper":"1.2.0"},"_hasShrinkwrap":false,"devDependencies":{"jest":"29.5.0","ts-jest":"29.1.0","ts-node":"10.9.1","typescript":"4.6.3","@types/jest":"29.5.0","@types/node":"17.0.23","@types/prettier":"2.6.0","@aws-mdaa/testing":"1.2.0","typescript-json-schema":"0.63.0"},"_npmOperationalInternal":{"tmp":"tmp/s3-bucketpolicy-helper_1.2.0_1760995512199_0.6075157727633305","host":"s3://npm-registry-packages-npm-production"}},"1.3.0":{"name":"@aws-mdaa/s3-bucketpolicy-helper","version":"1.3.0","author":{"url":"https://aws.amazon.com/solutions","name":"Amazon Web Services"},"license":"Apache-2.0","_id":"@aws-mdaa/s3-bucketpolicy-helper@1.3.0","maintainers":[{"name":"mdaa-dev-team","email":"mdaa-dev-team@amazon.com"}],"homepage":"https://github.com/aws/modern-data-architecture-accelerator#readme","bugs":{"url":"https://github.com/aws/modern-data-architecture-accelerator/issues"},"dist":{"shasum":"a7cf2ce38f25202526fb9c616a2aea5fc1228411","tarball":"https://registry.npmjs.org/@aws-mdaa/s3-bucketpolicy-helper/-/s3-bucketpolicy-helper-1.3.0.tgz","fileCount":4,"integrity":"sha512-VZmqPV/rHM5GgrOQmAJMzWJS+67cYg/ynLJuR7YL/A1Ifeq16hKHaIwuRk1HaitCFkQKSiSF2Kq1XdS5vj9K4g==","signatures":[{"sig":"MEUCIQD6cjd/mlWULVh2qYTrEDEEFO7OfDqNXal+Q3URoUIgugIgH5Mt8PIbUS/lv/0HAVCFO/XC4oJVEAd+5IqZAscaJWU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":41153},"main":"lib/index.js","_from":"file:/Users/guoneng/projects/mdaa/publications/us-east-1/1.3.0/mdaa-1.3.0/target/package-build/aws-mdaa-s3-bucketpolicy-helper-1.3.0.tgz","types":"lib/index.d.ts","gitHead":"8b49a2b371014baec046605ffdbfe38951099c31","scripts":{"lint":"eslint --max-warnings 0 -c ../../../.eslintrc.json '**/*.{ts,tsx}' --ignore-pattern 'dist/*' --ignore-pattern 'node_modules/*' --ignore-pattern \"*.d.ts\" ","test":"jest --passWithNoTests --coverage","build":"tsc","watch":"tsc -w","test-coverage":"jest --passWithNoTests --coverage"},"_npmUser":{"name":"mdaa-dev-team","email":"mdaa-dev-team@amazon.com"},"_resolved":"/Users/guoneng/projects/mdaa/publications/us-east-1/1.3.0/mdaa-1.3.0/target/package-build/aws-mdaa-s3-bucketpolicy-helper-1.3.0.tgz","overrides":{"aws-cdk-lib":"2.220.0","@types/babel__traverse":"7.18.2"},"_integrity":"sha512-VZmqPV/rHM5GgrOQmAJMzWJS+67cYg/ynLJuR7YL/A1Ifeq16hKHaIwuRk1HaitCFkQKSiSF2Kq1XdS5vj9K4g==","repository":{"url":"git+https://github.com/aws/modern-data-architecture-accelerator.git","type":"git"},"_npmVersion":"11.6.0","description":"MDAA s3-bucketpolicy-helper utility","directories":{},"_nodeVersion":"24.10.0","dependencies":{"cdk-nag":"2.37.55","constructs":"10.0.96","aws-cdk-lib":"2.220.0","@aws-mdaa/naming":"1.3.0","@aws-mdaa/iam-role-helper":"1.3.0"},"_hasShrinkwrap":false,"devDependencies":{"jest":"29.5.0","ts-jest":"29.1.0","ts-node":"10.9.1","typescript":"4.6.3","@types/jest":"29.5.0","@types/node":"17.0.23","@types/prettier":"2.6.0","@aws-mdaa/testing":"1.3.0","typescript-json-schema":"0.63.0"},"_npmOperationalInternal":{"tmp":"tmp/s3-bucketpolicy-helper_1.3.0_1764173473226_0.9574151724723412","host":"s3://npm-registry-packages-npm-production"}},"1.4.0":{"name":"@aws-mdaa/s3-bucketpolicy-helper","version":"1.4.0","author":{"url":"https://aws.amazon.com/solutions","name":"Amazon Web Services"},"license":"Apache-2.0","_id":"@aws-mdaa/s3-bucketpolicy-helper@1.4.0","maintainers":[{"name":"mdaa-dev-team","email":"mdaa-dev-team@amazon.com"}],"homepage":"https://github.com/aws/modern-data-architecture-accelerator#readme","bugs":{"url":"https://github.com/aws/modern-data-architecture-accelerator/issues"},"dist":{"shasum":"3775e3957f3d12c0d26fba66c720ac06c1da70f5","tarball":"https://registry.npmjs.org/@aws-mdaa/s3-bucketpolicy-helper/-/s3-bucketpolicy-helper-1.4.0.tgz","fileCount":4,"integrity":"sha512-Ox/+ykXq0VXzt6sT5MqxfZfc26xsB9q4UppMOCISNZMvKWRzlUfElXv6cKswkAnklugEbsKyC+9uWPL83e+S/w==","signatures":[{"sig":"MEQCIE2q9SmaML+ew8mIXFgqsR6uO+O9V5g/h84YXOLbKjabAiBPVydlGIBsqka6qJK7lrn9vzrMhwIOAAsqjxKNY3soMw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":41298},"main":"lib/index.js","_from":"file:/Users/guoneng/projects/mdaa/npm-publish/1.4.0/mdaa-1.4.0/target/package-build/aws-mdaa-s3-bucketpolicy-helper-1.4.0.tgz","types":"lib/index.d.ts","gitHead":"8b49a2b371014baec046605ffdbfe38951099c31","scripts":{"lint":"eslint --max-warnings 0 -c ../../../.eslintrc.json '**/*.{ts,tsx}' --ignore-pattern 'dist/*' --ignore-pattern 'node_modules/*' --ignore-pattern \"*.d.ts\" ","test":"jest --passWithNoTests --coverage","build":"tsc","watch":"tsc -w","test-coverage":"jest --passWithNoTests --coverage"},"_npmUser":{"name":"mdaa-dev-team","email":"mdaa-dev-team@amazon.com"},"_resolved":"/Users/guoneng/projects/mdaa/npm-publish/1.4.0/mdaa-1.4.0/target/package-build/aws-mdaa-s3-bucketpolicy-helper-1.4.0.tgz","_integrity":"sha512-Ox/+ykXq0VXzt6sT5MqxfZfc26xsB9q4UppMOCISNZMvKWRzlUfElXv6cKswkAnklugEbsKyC+9uWPL83e+S/w==","repository":{"url":"git+https://github.com/aws/modern-data-architecture-accelerator.git","type":"git"},"_npmVersion":"10.9.4","description":"MDAA s3-bucketpolicy-helper utility","directories":{},"_nodeVersion":"24.12.0","dependencies":{"cdk-nag":"2.37.55","constructs":"10.0.96","aws-cdk-lib":"2.220.0","@aws-mdaa/naming":"1.4.0","@aws-mdaa/iam-role-helper":"1.4.0"},"_hasShrinkwrap":false,"devDependencies":{"jest":"29.7.0","ts-jest":"29.4.6","ts-node":"10.9.2","typescript":"5.9.3","@types/jest":"29.5.14","@types/node":"22.9.0","@types/prettier":"2.6.0","@aws-mdaa/testing":"1.4.0","typescript-json-schema":"0.67.1"},"_npmOperationalInternal":{"tmp":"tmp/s3-bucketpolicy-helper_1.4.0_1770193516376_0.40559820551879255","host":"s3://npm-registry-packages-npm-production"}},"1.5.0":{"name":"@aws-mdaa/s3-bucketpolicy-helper","version":"1.5.0","author":{"url":"https://aws.amazon.com/solutions","name":"Amazon Web Services"},"license":"Apache-2.0","_id":"@aws-mdaa/s3-bucketpolicy-helper@1.5.0","maintainers":[{"name":"mdaa-dev-team","email":"mdaa-dev-team@amazon.com"}],"homepage":"https://github.com/aws/modern-data-architecture-accelerator#readme","bugs":{"url":"https://github.com/aws/modern-data-architecture-accelerator/issues"},"dist":{"shasum":"cbe8eff9da5bf933876574bf3dd39ae7aa009c97","tarball":"https://registry.npmjs.org/@aws-mdaa/s3-bucketpolicy-helper/-/s3-bucketpolicy-helper-1.5.0.tgz","fileCount":4,"integrity":"sha512-lhuHRd/0PcBiK7Qs1WgtBRe4gpVYNU6JfoeDBAYB+cMALlAJYP7vMx5DRI7EyEO8bMUik+4AuoMNukiInwU5CQ==","signatures":[{"sig":"MEYCIQDoqP4LHLoyq0avON0r1zuYQGRoRaQaX3tL4FQXPFZQEAIhAPEr1TPNvZcXWoW8CLNIw9GRFscTrz809suosHYOxXkg","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":41503},"main":"lib/index.js","_from":"file:/Users/suddash/Documents/MDAA/caef-delivery/1.5.0/mdaa-1.5.0/target/package-build/aws-mdaa-s3-bucketpolicy-helper-1.5.0.tgz","types":"lib/index.d.ts","gitHead":"8b49a2b371014baec046605ffdbfe38951099c31","scripts":{"lint":"eslint --max-warnings 0 -c ../../../eslint.config.mjs","test":"jest --passWithNoTests --testPathIgnorePatterns='.*\\.snapshot\\.test\\.ts'","build":"tsc","watch":"tsc -w","test:coverage":"jest --passWithNoTests --coverage --testPathIgnorePatterns='.*\\.snapshot\\.test\\.ts'","test:snapshots":"jest --passWithNoTests --testPathPattern='.*\\.snapshot\\.test\\.ts'","test:snapshots:update":"jest --passWithNoTests --testPathPattern='.*\\.snapshot\\.test\\.ts' --updateSnapshot"},"_npmUser":{"name":"mdaa-dev-team","email":"mdaa-dev-team@amazon.com"},"_resolved":"/Users/suddash/Documents/MDAA/caef-delivery/1.5.0/mdaa-1.5.0/target/package-build/aws-mdaa-s3-bucketpolicy-helper-1.5.0.tgz","_integrity":"sha512-lhuHRd/0PcBiK7Qs1WgtBRe4gpVYNU6JfoeDBAYB+cMALlAJYP7vMx5DRI7EyEO8bMUik+4AuoMNukiInwU5CQ==","repository":{"url":"git+https://github.com/aws/modern-data-architecture-accelerator.git","type":"git"},"_npmVersion":"10.9.2","description":"MDAA s3-bucketpolicy-helper utility","directories":{},"_nodeVersion":"23.9.0","dependencies":{"cdk-nag":"2.37.55","constructs":"10.0.96","aws-cdk-lib":"2.220.0","@aws-mdaa/naming":"1.5.0","@aws-mdaa/iam-role-helper":"1.5.0"},"_hasShrinkwrap":false,"devDependencies":{"jest":"29.7.0","ts-jest":"29.4.6","ts-node":"10.9.2","typescript":"5.9.3","@types/jest":"29.5.14","@types/node":"22.9.0","@types/prettier":"2.6.0","@aws-mdaa/testing":"1.5.0","typescript-json-schema":"0.67.1"},"_npmOperationalInternal":{"tmp":"tmp/s3-bucketpolicy-helper_1.5.0_1774537217534_0.9875813398912385","host":"s3://npm-registry-packages-npm-production"}},"1.6.0":{"name":"@aws-mdaa/s3-bucketpolicy-helper","version":"1.6.0","author":{"url":"https://aws.amazon.com/solutions","name":"Amazon Web Services"},"license":"Apache-2.0","_id":"@aws-mdaa/s3-bucketpolicy-helper@1.6.0","maintainers":[{"name":"mdaa-dev-team","email":"mdaa-dev-team@amazon.com"}],"homepage":"https://github.com/aws/modern-data-architecture-accelerator#readme","bugs":{"url":"https://github.com/aws/modern-data-architecture-accelerator/issues"},"dist":{"shasum":"84911740c24be3715fe0bbd8c2d141c3c93a4fe9","tarball":"https://registry.npmjs.org/@aws-mdaa/s3-bucketpolicy-helper/-/s3-bucketpolicy-helper-1.6.0.tgz","fileCount":4,"integrity":"sha512-LzafUhk4rp1BPBbRJG7PFCXuFbfscbmH3G60++Gb8JJF+o0CQkfiYg7r8ufxxezd3BSjJd8SSf9K5oM9sX8VKw==","signatures":[{"sig":"MEYCIQCk0d3iu0y2kW2PXbAG76NwH7Pg+Rzz2XpW01I6pbkYsgIhAMddi742hwKlk06pZVMkhju5t6MssOYY6M7gSCPsvEpG","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":41143},"main":"lib/index.js","_from":"file:/Users/guoneng/projects/mdaa/mdaa-pipeline/npmjs-build/mdaa/target/package-build/aws-mdaa-s3-bucketpolicy-helper-1.6.0.tgz","types":"lib/index.d.ts","gitHead":"8b49a2b371014baec046605ffdbfe38951099c31","scripts":{"lint":"eslint --max-warnings 0 -c ../../../eslint.config.mjs","test":"jest --passWithNoTests --coverage","build":"tsc","watch":"tsc -w","test:package-docs":"../../../scripts/generate_docs/test_package_docs.sh"},"_npmUser":{"name":"mdaa-dev-team","email":"mdaa-dev-team@amazon.com"},"_resolved":"/Users/guoneng/projects/mdaa/mdaa-pipeline/npmjs-build/mdaa/target/package-build/aws-mdaa-s3-bucketpolicy-helper-1.6.0.tgz","_integrity":"sha512-LzafUhk4rp1BPBbRJG7PFCXuFbfscbmH3G60++Gb8JJF+o0CQkfiYg7r8ufxxezd3BSjJd8SSf9K5oM9sX8VKw==","repository":{"url":"git+https://github.com/aws/modern-data-architecture-accelerator.git","type":"git"},"_npmVersion":"10.9.4","description":"MDAA s3-bucketpolicy-helper utility","directories":{},"_nodeVersion":"24.12.0","dependencies":{"cdk-nag":"2.37.55","constructs":"10.0.96","aws-cdk-lib":"2.220.0"},"_hasShrinkwrap":false,"devDependencies":{"jest":"29.7.0","ts-jest":"29.4.9","ts-node":"10.9.2","typescript":"5.9.3","@types/jest":"29.5.14","@types/node":"22.9.0","@types/prettier":"2.6.0","@aws-mdaa/testing":"1.6.0","typescript-json-schema":"0.67.4"},"_npmOperationalInternal":{"tmp":"tmp/s3-bucketpolicy-helper_1.6.0_1779447936707_0.18127053751802458","host":"s3://npm-registry-packages-npm-production"}},"1.7.0":{"name":"@aws-mdaa/s3-bucketpolicy-helper","description":"MDAA s3-bucketpolicy-helper utility","author":{"name":"Amazon Web Services","url":"https://aws.amazon.com/solutions"},"version":"1.7.0","license":"Apache-2.0","main":"lib/index.js","types":"lib/index.d.ts","scripts":{"build":"tsc","watch":"tsc -w","test":"jest --passWithNoTests --coverage","lint":"eslint --max-warnings 0 -c ../../../eslint.config.mjs","test:package-docs":"../../../scripts/generate_docs/test_package_docs.sh"},"devDependencies":{"@aws-mdaa/testing":"1.7.0","@types/jest":"29.5.14","@types/node":"22.9.0","@types/prettier":"2.6.0","jest":"29.7.0","ts-jest":"29.4.9","ts-node":"10.9.2","typescript":"5.9.3","typescript-json-schema":"0.67.4"},"dependencies":{"aws-cdk-lib":"2.258.0","cdk-nag":"2.37.55","constructs":"10.6.0"},"gitHead":"8b49a2b371014baec046605ffdbfe38951099c31","repository":{"type":"git","url":"git+https://github.com/aws/modern-data-architecture-accelerator.git"},"_id":"@aws-mdaa/s3-bucketpolicy-helper@1.7.0","bugs":{"url":"https://github.com/aws/modern-data-architecture-accelerator/issues"},"homepage":"https://github.com/aws/modern-data-architecture-accelerator#readme","_integrity":"sha512-MPtCGi2KQdiSKzfH337YpPziBHDY1SgY6ibRAEcXacAr1a26kHm1P95nSWo9zfR9Hwp733tgIcOeJGR410xckg==","_resolved":"/Users/guoneng/projects/mdaa/mdaa-pipeline/npmjs-build/mdaa/target/package-build/aws-mdaa-s3-bucketpolicy-helper-1.7.0.tgz","_from":"file:/Users/guoneng/projects/mdaa/mdaa-pipeline/npmjs-build/mdaa/target/package-build/aws-mdaa-s3-bucketpolicy-helper-1.7.0.tgz","_nodeVersion":"24.12.0","_npmVersion":"10.9.4","dist":{"integrity":"sha512-MPtCGi2KQdiSKzfH337YpPziBHDY1SgY6ibRAEcXacAr1a26kHm1P95nSWo9zfR9Hwp733tgIcOeJGR410xckg==","shasum":"32f77149948dd015f3520c9f1fdcdbc032d2f680","tarball":"https://registry.npmjs.org/@aws-mdaa/s3-bucketpolicy-helper/-/s3-bucketpolicy-helper-1.7.0.tgz","fileCount":4,"unpackedSize":41142,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIETwHugkP4vFwa/DW5xPU/tOtEZU18+u3cuP6Ed6WlhaAiA3Ysujaq2rLA5K7vlzzKcFDOdxlrWXUIiEx9aESrbgPA=="}]},"_npmUser":{"name":"mdaa-dev-team","email":"mdaa-dev-team@amazon.com"},"directories":{},"maintainers":[{"name":"mdaa-dev-team","email":"mdaa-dev-team@amazon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/s3-bucketpolicy-helper_1.7.0_1784277911250_0.9025096506184529"},"_hasShrinkwrap":false}},"time":{"created":"2025-10-20T21:25:12.106Z","modified":"2026-07-17T08:45:11.528Z","1.2.0":"2025-10-20T21:25:12.387Z","1.3.0":"2025-11-26T16:11:13.571Z","1.4.0":"2026-02-04T08:25:16.526Z","1.5.0":"2026-03-26T15:00:17.677Z","1.6.0":"2026-05-22T11:05:36.862Z","1.7.0":"2026-07-17T08:45:11.382Z"},"bugs":{"url":"https://github.com/aws/modern-data-architecture-accelerator/issues"},"author":{"name":"Amazon Web Services","url":"https://aws.amazon.com/solutions"},"license":"Apache-2.0","homepage":"https://github.com/aws/modern-data-architecture-accelerator#readme","repository":{"type":"git","url":"git+https://github.com/aws/modern-data-architecture-accelerator.git"},"description":"MDAA s3-bucketpolicy-helper utility","maintainers":[{"name":"mdaa-dev-team","email":"mdaa-dev-team@amazon.com"}],"readme":"# S3 Bucket Policy Helper\n\nThis is a helper class that helps construct working S3 Bucket policy statements that can be added to a bucket construct.\n\n## Class RestrictObjectPrefixToRoles\n\nThis helper class helps construct a working policy that allows a group of Roles to access to an object prefix in S3.\n\nDepending on the values provided, it will produce two PolicyStatement types accessible by methods.\n\nOne for Read access to an object prefix that generally resolves to:\n\n```yaml\n- Action: s3:GetObject*\n  Condition:\n    StringLike:\n      aws:userId:\n        - AROA12345678:*\n  Effect: Allow\n  Principal: \"*\"\n  Resource:\n    Fn::Join:\n      - \"\"\n      - - Fn::GetAtt:\n            - BuckettransformedCbdgadDatalakeTransformedPrototype20210115E093F710\n            - Arn\n        - /inventory/*\n  Sid: inventory/Read\n```\n\nOne for write access to an object prefix that generally resolves to:\n\n```yaml\n- Action:\n    - s3:GetObject*\n    - s3:PutObject*\n    - s3:DeleteObject*\n  Condition:\n    StringLike:\n      aws:userId:\n        - AROA12345678:*\n  Effect: Allow\n  Principal: \"*\"\n  Resource:\n    Fn::Join:\n      - \"\"\n      - - Fn::GetAtt:\n            - BuckettransformedCbdgadDatalakeTransformedPrototype20210115E093F710\n            - Arn\n        - /inventory/*\n  Sid: inventory/ReadWrite\n```\n\nConditionals against `aws:userId` are used to support federated roles.  The `@aws-mdaa/iam-role-helper` is used to resolve the requested ARNs to AROA IDs.\n\n## RestrictObjectPrefixToRoles example\n\n```typescript\nimport {MdaaRoleResolver} from '@aws-mdaa/am-role-helper'\nimport {RestrictObjectPrefixToRoles} from '@aws-mdaa/3-bucketpolicy-helper'\n\nconst roleResolver = new MdaaRoleResolver({\n    roleArns: [\n        'arn:{{partition}}:iam::{{account}}:role/application_abc/component_xyz/S3Access',\n        'arn:{{partition}}:iam::{{account}}:role/service-role/QuickSightAction'\n    ]\n})\n\nroleResolver.init().then(() => {\n    const RestrictPrefix = new RestrictObjectPrefixToRoles({\n        // bucket in this context is a constructed s3.Bucket class\n        s3Bucket: bucket,\n        s3Prefix: '/protected',\n        readRoles: [\n            'arn:{{partition}}:iam::{{account}}:role/application_abc/component_xyz/S3Access',\n            'arn:{{partition}}:iam::{{account}}:role/service-role/QuickSightAction'\n        ],\n        readWriteRoles: [\n            'arn:{{partition}}:iam::{{account}}:role/application_abc/component_xyz/S3Access'\n        ],\n        roleAroaResolver: roleResolver\n    })\n    \n    bucket.addToResourcePolicy(RestrictPrefix.readStatement())\n    bucket.addToResourcePolicy(RestrictPrefix.readWriteStatement())\n})\n```\n\n## Class RestrictBucketToRoles\n\nHelper class to construct a policy that will restrict a bucket to a set of roles.  This is realized through a Deny where source role is not on the list, and an Allow where source role is.\n\nDepending on the values provided, it will produce two PolicyStatement types accessible by methods.\n\nOne for general bucket access that resolves to:\n\n```yaml\n          - Action:\n              - s3:List*\n              - s3:GetBucket*\n            Condition:\n              StringLike:\n                aws:userId:\n                  - AROA12345678:*\n            Effect: Allow\n            Principal: \"*\"\n            Resource:\n              - Fn::Join:\n                  - \"\"\n                  - - Fn::GetAtt:\n                        - BuckettransformedCbdgadDatalakeTransformedPrototype20210115E093F710\n                        - Arn\n                    - /*\n              - Fn::GetAtt:\n                  - BuckettransformedCbdgadDatalakeTransformedPrototype20210115E093F710\n                  - Arn\n            Sid: BucketAllow\n```\n\nOne that denies access to the bucket that resolves to:\n\nNOTE: To permit things like inventory we exclude the s3 service from the Deny statements.  Also since we're using a NotPrincipal statement, we also include the root account to assure access to the bucket isn't lost if the Roles are deleted.\n\n```yaml\n          - Action:\n              - s3:PutObject*\n              - s3:GetObject*\n              - s3:List*\n              - s3:GetBucket*\n            Condition:\n              StringNotLike:\n                aws:userId:\n                  - AROA12345678:*\n            Effect: Deny\n            NotPrincipal:\n              Service: s3.amazonaws.com\n              AWS:\n                Fn::Join:\n                  - \"\"\n                  - - \"arn:\"\n                    - Ref: AWS::Partition\n                    - \":iam::\"\n                    - Ref: AWS::AccountId\n                    - :root\n            Resource:\n              - Fn::Join:\n                  - \"\"\n                  - - Fn::GetAtt:\n                        - BuckettransformedCbdgadDatalakeTransformedPrototype20210115E093F710\n                        - Arn\n                    - /*\n              - Fn::GetAtt:\n                  - BuckettransformedCbdgadDatalakeTransformedPrototype20210115E093F710\n                  - Arn\n            Sid: BucketDeny\n```\n\n## RestrictBucketToRoles example\n\n```typescript\nimport {MdaaRoleResolver} from '@aws-mdaa/am-role-helper'\nimport {RestrictBucketToRoles} from '@aws-mdaa/3-bucketpolicy-helper'\n\nconst roleResolver = new MdaaRoleResolver({\n    roleArns: [\n        'arn:{{partition}}:iam::{{account}}:role/application_abc/component_xyz/S3Access',\n        'arn:{{partition}}:iam::{{account}}:role/service-role/QuickSightAction'\n    ]\n})\n\nroleResolver.init().then(() => {\n    const RestrictBucket = new RestrictBucketToRoles({\n        // bucket in this context is a constructed s3.Bucket class\n        s3Bucket: bucket,\n        roles: [\n            'arn:{{partition}}:iam::{{account}}:role/application_abc/component_xyz/S3Access',\n            'arn:{{partition}}:iam::{{account}}:role/service-role/QuickSightAction'\n        ],\n        roleAroaResolver: roleResolver\n    })\n    \n    bucket.addToResourcePolicy(RestrictBucket.allowStatement())\n    bucket.addToResourcePolicy(RestrictBucket.denyStatement())\n})\n```\n","readmeFilename":"README.md"}