2024/10/5 YAPC::Hakodate 2024

2024/10/5 YAPC::Hakodate 2024
Security.Tokyo #3ã®çºè¡¨è³æã§ãã ã¯ã©ã¤ã¢ã³ããµã¤ãã®ãã¹ãã©ãã¼ãµã«ã¨ãpostMessageçµç±ã®èå¼±æ§ãåãä¸ãã¾ããã
ã¯ããã« ããã«ã¡ã¯ãæ ªå¼ä¼ç¤¾Flatt Security ã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ã®æ£®å²¡(@scgajge12)ã§ãã æ¬ç¨¿ã§ã¯ãAmazon S3 ã®èå¼±ãªä½¿ãæ¹ã«ããã»ãã¥ãªãã£ãªã¹ã¯ã¨å¯¾çã解説ããå®éã®è¨å®ä¸åãªã©ã«é¢ããäºä¾ã«ã¤ãã¦ãç´¹ä»ãã¾ãã Flatt Security ã¯å°é家ã®è¦ç¹ã§ã»ãã¥ãªãã£ãªã¹ã¯ã調æ»ããã»ãã¥ãªãã£è¨ºæãæä¾ãã¦ãã¾ããã¯ã©ã¦ãã¨ã¢ããªã±ã¼ã·ã§ã³ã®ç·åçãªè¨ºæã®äºä¾ã¨ã㦠SmartHR æ§ã®è¨ºæäºä¾ããããã¾ãã®ã§ãæ¯éã¤ã³ã¿ãã¥ã¼è¨äºãã覧ãã ãããGCP ã®äºä¾ã§ããããã¡ããä»ååãä¸ãã AWS ã§ãåæ§ã®è¨ºæãå¯è½ã§ãã ã¯ããã« Amazon S3 ã¨ã¯ ãã±ããã»ãªãã¸ã§ã¯ã ãã±ãã ãªãã¸ã§ã¯ã ã¢ã¯ã»ã¹ããªã·ã¼ ãã±ããããªã·ã¼ ã¢ã¯ã»ã¹ã³ã³ããã¼ã«ãªã¹ã(ACL) IAM ããªã·ã¼ ç½²åä»ã URL Amazon S3 ã«
ãç¥ãã
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}