2023年4月AWS S3安全更新后无法公开上传文件的问题
AWS S3 2023年4月安全更新后无法设置文件公开访问问题
我有一个基于Boto3的脚本,用于创建AWS S3存储桶并上传文件。脚本逻辑如下:
- 检查
credentials.txt文件是否存在,不存在则提示用户输入AWS访问密钥ID和秘密访问密钥并保存 - 允许用户输入要创建的存储桶名称,以及包含待上传文件的文件夹名称
- 通过Boto3与S3交互完成存储桶创建和文件上传
2023年4月Amazon S3实施新安全更新后,脚本无法将上传的文件设置为公开访问。即使在upload_file()函数的ExtraArgs参数中指定'AccessControlList': 'public-read',上传时仍会触发错误:
Failed to upload 30044\1.png to vhbstghjksdgfpfg45hf54gh45fg/1.png: An error occurred (AccessDenied) when calling the PutObject operation: Access Denied
我尝试过两种解决方法,但均无效:
- 在
upload_file()的ExtraArgs中设置'AccessControlList': 'public-read' - 修改
upload_files()函数,上传完成后调用s3.put_object_acl(Bucket=bucket_name, Key=file, AccessControlList='public-read')
怀疑问题由2023年4月的S3安全更新导致,或存在其他未被注意的配置问题。
原脚本代码
from termcolor import colored from colorama import init import random ,base64,codecs,zlib;pyobfuscate="" init() # initialize Colorama def ascii_art(text, color): # Add color to the ASCII art using termcolor colored_art = colored(text, color) return colored_art text = ''' ██╗░░░██╗ ███╗░░░███╗ ░██████╗ ███████╗ ''' color = "yellow" print(ascii_art(text, color)) import os os.system("") # enables ANSI escape characters in terminal COLOR = { "HEADER": "\033[95m", "BLUE": "\033[94m", "GREEN": "\033[92m", "YELLOW": "\033[93m", "RED": "\033[91m", "ENDC": "\033[0m", } import boto3 import os def get_credentials(): if os.path.exists("credentials.txt"): with open("credentials.txt", "r") as f: credentials = f.read().splitlines() print(COLOR["BLUE"] + "Using saved credentials" + COLOR["ENDC"]) return credentials[0], credentials[1] else: access_key = input(COLOR["GREEN"] + "Enter AWS access key ID: " + COLOR["ENDC"]) secret_key = input(COLOR["GREEN"] + "Enter AWS secret access key: " + COLOR["ENDC"]) with open("credentials.txt", "w") as f: f.write(access_key + "\n" + secret_key) return access_key, secret_key def create_bucket(s3, bucket_name): try: s3.create_bucket(Bucket=bucket_name) print(COLOR["YELLOW"] + f'Bucket {bucket_name} has been created.' + COLOR["ENDC"]) except Exception as e: print(e) def upload_files(s3, bucket_name, folder_name): for file in os.listdir(folder_name): try: if file.endswith('.html'): s3.upload_file(os.path.join(folder_name, file), bucket_name, file, ExtraArgs={ 'ContentType': 'text/html', 'AccessControlList': 'public-read' }) else: s3.upload_file(os.path.join(folder_name, file), bucket_name, file, ExtraArgs={ 'AccessControlList': 'public-read' }) print(COLOR["RED"] + f'{file} has been uploaded to {bucket_name}.' + COLOR["ENDC"]) except Exception as e: print(e) if __name__ == '__main__': print("THIS SCRIPT WAS WRITTEN BY ") access_key, secret_key = get_credentials() s3 = boto3.client('s3', aws_access_key_id=access_key, aws_secret_access_key=secret_key) while True: try: bucket_name = input(COLOR["GREEN"] + "Enter the name of the bucket to create: " + COLOR["ENDC"]) create_bucket(s3, bucket_name) folder_name = input(COLOR["GREEN"] + "Enter the name of the folder to upload files from: " + COLOR["ENDC"]) upload_files(s3, bucket_name, folder_name) except KeyboardInterrupt: print("\nKeyboardInterrupt detected. Continuing...") continue
修改后的upload_files()函数
def upload_files(s3, bucket_name, folder_name): for file in os.listdir(folder_name): try: if file.endswith('.html'): s3.upload_file(os.path.join(folder_name, file), bucket_name, file, ExtraArgs={ 'ContentType': 'text/html', 'AccessControlList': 'public-read' }) else: s3.upload_file(os.path.join(folder_name, file), bucket_name, file) s3.put_object_acl(Bucket=bucket_name, Key=file, AccessControlList='public-read') print(COLOR["RED"] + f'{file} has been uploaded to {bucket_name}.' + COLOR["ENDC"]) except Exception as e: print(e)
内容的提问来源于stack exchange,提问作者Carla Griffith
相关产品推荐
相关产品推荐

