Currently, we specify the root account as the Principle in the permissions we tell users to apply to their buckets, so if a user knew another user's bucket name, they could publish products to another users' bucket. This will still be true with the more restrictive permissions in #3108.
I don't know of a way to add a condition or change how we set stuff up in AWS to allow restricting permissions to an Earthdata login user name, or set of user names... Is there a way?
Currently, we specify the root account as the Principle in the permissions we tell users to apply to their buckets, so if a user knew another user's bucket name, they could publish products to another users' bucket. This will still be true with the more restrictive permissions in #3108.
I don't know of a way to add a condition or change how we set stuff up in AWS to allow restricting permissions to an Earthdata login user name, or set of user names... Is there a way?