Isolate one tenant
Your team keeps every customer's rows in one shared DynamoDB table, one partition key per tenant. The reports service reads that table on behalf of whoever is signed in, and it currently carries the AWS managed policy somebody attached in a hurry.
Open the Tenant isolation console and read what that managed policy hands back. Then switch to the customer managed one, which is where the video's dynamodb:LeadingKeys condition lives, and work through the actions its statement grants.
The condition denies two of the five requests on its own. That is still not isolation.
Which change finally stops the caller reading another tenant's rows?
Bài tập này là một phần của khóa học
Using AWS Security for Developers
Bài tập tương tác thực hành
Biến lý thuyết thành hành động với một trong các bài tập tương tác của chúng tôi
Bắt đầu bài tập