Add the authenticated users URI as a Grantee URI to check #1
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
The "Authenticated Users group" predefined group is also a group that can be in an ACL that grants effective public access to an S3 bucket:
This PR adds the group and checks for it.
Public access at the bucket level could also be done via bucket policy, but that's a bit tricker than just knowing a couple predefined groups to check for on an ACL and is outside the scope of this PR.