← Live-лента

[AWS/Laravel] S3 Security: Migrating to Signed URLs & Blocking Public Access (Timebox: 10 hours)

Бюджет: $125.0 FIXED / ⭐ 0.00 (0) COL

amazon-s3, mysql, php, laravel-framework, angular

Preferred qualifications

  • Experience: Expert
Context & Objective: Currently, the files stored in our AWS S3 bucket have public access. Due to security policies, we need to restrict this access immediately. The objective of this milestone is to block public access to the bucket and refactor the document upload/download flow using Signed URLs with an expiration time, ensuring a seamless user experience on the frontend. Scope of Work: A 10-hour block of work is estimated, which includes research time (onboarding to the current architecture) and the execution of the following tasks: 1. AWS & DevOps: Modify S3 bucket policies to completely block public access (enable Block Public Access - BPA). Review and update calls in existing Lambdas to ensure they continue working correctly under the new restrictive permission model (if applicable). 2. Backend (API/Laravel): Modify the corresponding endpoints to return an S3 Signed URL instead of the direct public URL when requesting document read/download. 3. Frontend: Implement the logic to handle the expiration of Signed URLs. If a user attempts to view a document and the URL has already expired, the frontend must silently request a new signed URL from the backend and reload the resource without interrupting the user experience. 4. Automated Testing (AI-Assisted): Develop automated tests covering: Document upload and download. Correct generation of Signed URLs. Signature regeneration from the frontend when the current one has expired. Acceptance Criteria (Definition of Done): To consider the milestone completed and proceed with the payment release, the following must be strictly met: [ ] Functional Evidence (Asynchronous Video): Delivery of a short video (e.g., Loom) demonstrating: Attempting direct access to a bucket file via browser showing that it is blocked (403 Error). Successful upload and display of a document on the platform using the new Signed URL. Simulation of an expired URL showing how the frontend intercepts the error, requests a new signature, and displays the file without breaking the UI. [ ] Code & Testing: The automated tests described in the scope must execute successfully in the environment without breaking existing pipelines. [ ] Code Review (PR/MR): The code must be delivered via a clean Pull Request or Merge Request, following project standards. [ ] Tech Lead Approval: The PR must be explicitly reviewed and approved by the Technical Lead, validating architecture, security, and logic.
Открыть заказ

AI-черновик отклика

Короткий текст отклика для копирования в оффер: интерес + готовность работать.

Войдите, чтобы сгенерировать AI-черновик.

Войти