v4.1.4 requires s3:ListAllMyBuckets
-
G’day BackWPup,
If the subject line sounds vaguely familiar, it’s because this bug is a retread of one from July 2019.
It was once possible to create a backup job for an S3 bucket without having the
s3:ListAllMyBuckets
privilege. When an API key had no such privilege, the drop-down list of buckets was replaced by a text field. Now, an API error is displayed when the policy doesn’t have that privilege.This a security problem and must not be required for a secure backup. The API key for one website should not be able to list the S3 buckets of other websites in the same AWS account. Can we please have the previous functionality back? It was one of the features that first drew me to this plugin.
cheers,
Ross
- You must be logged in to reply to this topic.