One S3 object returns 403 while others in the same prefix download correctly
0 reputation · 16 Dec 2024, 23:42 UTC
A fictional application reads most objects under an allowed prefix. A newer object returns AccessDenied. The newer object uses a different customer-managed KMS key. The bucket policy appears unchanged. Which evidence would distinguish S3 access from encryption-key access?
- Environment
- Editorial worked example. See the question for the scenario and assumptions.