Title: Privilege Level Concern
Last modified: August 22, 2016

---

# Privilege Level Concern

 *  Resolved [Nick Haskins](https://wordpress.org/support/users/nphaskins/)
 * (@nphaskins)
 * [11 years, 8 months ago](https://wordpress.org/support/topic/privilege-level-concern/)
 * There’s some concern from our sys admin about the level of privileges here, specifically“
   deleting buckets.” Is this filterable perhaps? The level of privs that is.
 * [https://wordpress.org/plugins/amazon-s3-and-cloudfront/](https://wordpress.org/plugins/amazon-s3-and-cloudfront/)

Viewing 7 replies - 1 through 7 (of 7 total)

 *  Plugin Contributor [Iain Poulson](https://wordpress.org/support/users/polevaultweb/)
 * (@polevaultweb)
 * [11 years, 8 months ago](https://wordpress.org/support/topic/privilege-level-concern/#post-5724531)
 * Hi Nick
 * The plugin does not allow anyone to delete buckets.
 * The plugin’s settings, where you can create buckets, is limited to admins with
   the ‘manage_options’ capability or for Multisites those with ‘manage_network_options’.
 * Let me know if you need any further info.
 *  Thread Starter [Nick Haskins](https://wordpress.org/support/users/nphaskins/)
 * (@nphaskins)
 * [11 years, 8 months ago](https://wordpress.org/support/topic/privilege-level-concern/#post-5724532)
 * HI! While the UI doesn’t have the ability to do that, the level of permissions
   that this plugin needs for S3 does. Meaning, all an attacker needs is the keys
   and they can completely delete a bucket.
 * If this plugin doesn’t have this feature, then why does it need that level of
   priv?
 *  Plugin Contributor [Iain Poulson](https://wordpress.org/support/users/polevaultweb/)
 * (@polevaultweb)
 * [11 years, 8 months ago](https://wordpress.org/support/topic/privilege-level-concern/#post-5724533)
 * If you use the plugin with an AWS [IAM user](https://console.aws.amazon.com/iam/home?region=us-east-1#users)
   you can control the permissions and not allow deleting of buckets.
 * The only delete permission the user needs for the plugin is DeleteObject
 *  Thread Starter [Nick Haskins](https://wordpress.org/support/users/nphaskins/)
 * (@nphaskins)
 * [11 years, 8 months ago](https://wordpress.org/support/topic/privilege-level-concern/#post-5724534)
 * That’s actually incorrect. I’ve tried creating various roles, and every single
   time I get hit back with the error that this is the minimum that is required 
   for your plugin to operate:
 * {
    “Version”: “2012-10-17”, “Statement”: [ { “Effect”: “Allow”, “Action”: “s3:*”,“
   Resource”: “*” } ] }
 * The plugin will not function without complete access to S3.
 *  Thread Starter [Nick Haskins](https://wordpress.org/support/users/nphaskins/)
 * (@nphaskins)
 * [11 years, 8 months ago](https://wordpress.org/support/topic/privilege-level-concern/#post-5724536)
 * Just a note, I double checked the policy and DeleteObject was indeed missing.
   I’ve generated a new policy that excludes deleting buckets and this does seem
   to work. I would recc changing your warning with an example policy that’s not
   so wide open.
 * Thanks for your help, and for a wonderful plugin.
 *  Plugin Contributor [Iain Poulson](https://wordpress.org/support/users/polevaultweb/)
 * (@polevaultweb)
 * [11 years, 8 months ago](https://wordpress.org/support/topic/privilege-level-concern/#post-5724538)
 * Thanks Nick, was about to send you this and say the same, we need to update our
   example 🙂
 * {
    “Version”: “2012-10-17”, “Statement”: [ { “Sid”: “Stmt1422543245111”, “Effect”:“
   Allow”, “Action”: [ “s3:CreateBucket”, “s3:DeleteObject”, “s3:Put*”, “s3:Get*”,“
   s3:List*” ], “Resource”: [ “arn:aws:s3:::*” ] } ] }
 *  Thread Starter [Nick Haskins](https://wordpress.org/support/users/nphaskins/)
 * (@nphaskins)
 * [11 years, 8 months ago](https://wordpress.org/support/topic/privilege-level-concern/#post-5724540)
 * OH shit! That’s way more simplified than what I”ve got. Nice on the wildcards.
   Thanks again!!

Viewing 7 replies - 1 through 7 (of 7 total)

 The topic ‘Privilege Level Concern’ is closed to new replies.

 * ![](https://ps.w.org/amazon-s3-and-cloudfront/assets/icon-256x256.jpg?rev=1809890)
 * [WP Offload Media Lite for Amazon S3, DigitalOcean Spaces, and Google Cloud Storage](https://wordpress.org/plugins/amazon-s3-and-cloudfront/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/amazon-s3-and-cloudfront/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/amazon-s3-and-cloudfront/)
 * [Active Topics](https://wordpress.org/support/plugin/amazon-s3-and-cloudfront/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/amazon-s3-and-cloudfront/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/amazon-s3-and-cloudfront/reviews/)

 * 7 replies
 * 2 participants
 * Last reply from: [Nick Haskins](https://wordpress.org/support/users/nphaskins/)
 * Last activity: [11 years, 8 months ago](https://wordpress.org/support/topic/privilege-level-concern/#post-5724540)
 * Status: resolved