You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Amplify Storage权限问题:带组用户无法执行S3 .put操作

Amplify Storage 用户组用户上传AccessDenied问题解决方法

问题背景

配置Amplify Storage并设置Auth/Guest用户权限后,普通认证用户可正常上传文件至S3,但归属admin用户组的用户执行.put操作时提示AccessDenied。尝试配置IAM角色和用户组权限无效,需通过修改S3 CloudFormation模板的认证策略解决;切换到"Individual Groups"权限模式时,admin用户操作正常,但访客权限失效。

配置命令

原始Auth/Guest配置:

amplify update storage
? Select from one of the below mentioned services: Content (Images, audio, video, etc.)
✔ Restrict access by? · Auth/Guest Users
✔ Who should have access: · Auth and guest users
✔ What kind of access do you want for Authenticated users? · create/update, read, delete
✔ What kind of access do you want for Guest users? · create/update
✔ Select from the following options · Skip Question
✅ Successfully updated resource

用户组配置:

amplify update storage
? Select from one of the below mentioned services: Content (Images, audio, video, etc.)
✔ Restrict access by? · Individual Groups
✔ Select groups: · admin
✔ What kind of access do you want for admin users? · create/update, read, delete
✔ Select from the following options · Skip Question

解决方案

核心问题是Amplify默认Auth用户策略未包含用户组条件判断,导致用户组用户请求被S3拒绝。需手动修改Storage的CloudFormation模板,在认证用户策略中添加用户组允许条件。

具体操作步骤

  1. 定位Amplify项目中Storage的CloudFormation模板文件,路径通常为:amplify/backend/storage/<你的存储资源名称>/<资源名称>-cloudformation-template.json
  2. 打开文件后,找到Resources下的AuthPolicy资源(类型为AWS::IAM::Policy)
  3. 在该策略的PolicyDocument.Statement中,定位针对认证用户的Effect: Allow语句(对应Principal: { AWS: "!GetAtt AuthRole.Arn" }的条目)
  4. 在该语句的Condition部分添加用户组判断条件,示例如下:
    "Condition": {
      "StringEquals": {
        "s3:prefix": [
          "public/",
          "protected/${cognito-identity.amazonaws.com:sub}/",
          "private/${cognito-identity.amazonaws.com:sub}/"
        ]
      },
      "ForAnyValue:StringLike": {
        "cognito:groups": ["admin"]
      }
    }
    
    若需保留所有认证用户权限,同时允许admin组用户,可调整为:
    "Condition": {
      "Or": [
        {
          "StringEquals": {
            "s3:prefix": [
              "public/",
              "protected/${cognito-identity.amazonaws.com:sub}/",
              "private/${cognito-identity.amazonaws.com:sub}/"
            ]
          }
        },
        {
          "ForAnyValue:StringLike": {
            "cognito:groups": ["admin"]
          }
        }
      ]
    }
    
  5. 保存文件后执行amplify push部署更新配置
  6. 验证admin用户组用户的.put操作,同时确认普通认证用户和访客权限正常

额外说明

切换到"Individual Groups"模式时,Amplify会自动移除访客相关策略配置,因此若需同时保留访客权限,必须在Auth/Guest模式基础上手动添加用户组权限策略,不能直接使用该模式。

注意事项

  • 后续执行amplify update storage可能覆盖手动修改的模板内容,建议备份模板或记录修改点
  • 确保条件中的用户组名称与Cognito中创建的组名完全一致
  • 测试需使用已加入admin组的真实用户账号

内容的提问来源于stack exchange,提问作者Elia Weiss

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.26 20:37:27