Skip to content

Commit

Permalink
test assumed role (#3621)
Browse files Browse the repository at this point in the history
  • Loading branch information
kddejong authored Aug 27, 2024
1 parent 37aaa9e commit a34f16c
Show file tree
Hide file tree
Showing 2 changed files with 29 additions and 0 deletions.
3 changes: 3 additions & 0 deletions src/cfnlint/data/schemas/other/iam/policy.json
Original file line number Diff line number Diff line change
Expand Up @@ -28,6 +28,9 @@
{
"pattern": "^arn:(aws|aws-cn|aws-us-gov):iam::\\d{12}:(?:root|user|group|role)"
},
{
"pattern": "^arn:(aws|aws-cn|aws-us-gov):sts::\\d{12}:assumed-role"
},
{
"pattern": "^arn:(aws|aws-cn|aws-us-gov):iam::cloudfront:user/.+$"
}
Expand Down
26 changes: 26 additions & 0 deletions test/unit/rules/resources/iam/test_resource_policy.py
Original file line number Diff line number Diff line change
Expand Up @@ -224,3 +224,29 @@ def test_principal_wildcard(self):
)
)
self.assertListEqual(errs, [])

def test_assumed_role(self):
validator = CfnTemplateValidator({}).evolve(
context=Context(functions=FUNCTIONS)
)

policy = {
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": "*",
"Resource": "arn:aws:s3:::bucket",
"Principal": {
"AWS": "arn:aws:sts::123456789012:assumed-role/rolename/rolesessionname"
},
},
],
}

errs = list(
self.rule.validate(
validator=validator, policy=policy, schema={}, policy_type=None
)
)
self.assertListEqual(errs, [])

0 comments on commit a34f16c

Please sign in to comment.