UNPKG

iam-floyd

Version:

AWS IAM policy statement generator with fluent interface

841 lines 82.6 kB
"use strict"; Object.defineProperty(exports, "__esModule", { value: true }); exports.Securityagent = void 0; const shared_1 = require("../../shared"); /** * Statement provider for service [securityagent](https://docs.aws.amazon.com/service-authorization/latest/reference/list_awssecurityagent.html). * * @param sid [SID](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_elements_sid.html) of the statement */ class Securityagent extends shared_1.PolicyStatement { /** * Statement provider for service [securityagent](https://docs.aws.amazon.com/service-authorization/latest/reference/list_awssecurityagent.html). * * @param sid [SID](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_elements_sid.html) of the statement */ constructor(sid) { super(sid); this.servicePrefix = 'securityagent'; this.accessLevelList = { Write: [ 'AddArtifact', 'AddControl', 'BatchDeletePentests', 'CreateAgentInstance', 'CreateApplication', 'CreateDocumentReview', 'CreateIntegration', 'CreateMembership', 'CreateOneTimeLoginSession', 'CreatePentest', 'DeleteAgentInstance', 'DeleteApplication', 'DeleteArtifact', 'DeleteControl', 'DeleteIntegration', 'DeleteMembership', 'HandleOneTimeLoginSession', 'InitiateProviderRegistration', 'StartCodeRemediation', 'StartPentestExecution', 'StopPentestExecution', 'ToggleManagedControl', 'UpdateAgentInstance', 'UpdateApplication', 'UpdateControl', 'UpdateFinding', 'UpdateIntegratedResources', 'UpdatePentest', 'VerifyTargetDomain' ], Read: [ 'BatchGetAgentInstances', 'BatchGetArtifactMetadata', 'BatchGetFindings', 'BatchGetPentestJobs', 'BatchGetPentests', 'BatchGetSecurityTestContentMetadata', 'BatchGetTasks', 'DescribeFindings', 'GetApplication', 'GetArtifact', 'GetCodeReviewTask', 'GetControl', 'GetDocReviewTask', 'GetDocumentReview', 'GetDocumentReviewArtifact', 'GetIntegration', 'GetLoginSessionCredentials' ], List: [ 'ListAgentInstanceTasks', 'ListAgentInstances', 'ListApplications', 'ListArtifacts', 'ListControls', 'ListDiscoveredEndpoints', 'ListDocumentReviewComments', 'ListDocumentReviews', 'ListFindings', 'ListIntegratedResources', 'ListIntegrations', 'ListMemberships', 'ListPentestJobsForPentest', 'ListPentests', 'ListResourcesFromIntegration', 'ListTasks' ] }; } /** * Grants permission to add an Artifact for the given Agent Instance * * Access Level: Write * * https://docs.aws.amazon.com/securityagent/API_AddArtifact.html */ toAddArtifact() { return this.to('AddArtifact'); } /** * Grants permission to add a customer managed Control * * Access Level: Write * * https://docs.aws.amazon.com/securityagent/API_AddControl.html */ toAddControl() { return this.to('AddControl'); } /** * Grants permission to delete multiple penetration tests in a single request * * Access Level: Write * * https://docs.aws.amazon.com/securityagent/API_BatchDeletePentests.html */ toBatchDeletePentests() { return this.to('BatchDeletePentests'); } /** * Grants permission to retrieve multiple agent instances in a single request * * Access Level: Read * * https://docs.aws.amazon.com/securityagent/API_BatchGetAgentInstances.html */ toBatchGetAgentInstances() { return this.to('BatchGetAgentInstances'); } /** * Grants permission to retrieve one or more Artifact Metadata records for the given Agent Instance * * Access Level: Read * * https://docs.aws.amazon.com/securityagent/API_BatchGetArtifactMetadata.html */ toBatchGetArtifactMetadata() { return this.to('BatchGetArtifactMetadata'); } /** * Grants permission to retrieve multiple security testing findings in a single request * * Access Level: Read * * https://docs.aws.amazon.com/securityagent/API_BatchGetFindings.html */ toBatchGetFindings() { return this.to('BatchGetFindings'); } /** * Grants permission to retrieve multiple security testing jobs in a single request * * Access Level: Read * * https://docs.aws.amazon.com/securityagent/API_BatchGetPentestJobs.html */ toBatchGetPentestJobs() { return this.to('BatchGetPentestJobs'); } /** * Grants permission to retrieve multiple penetration tests in a single request * * Access Level: Read * * https://docs.aws.amazon.com/securityagent/API_BatchGetPentests.html */ toBatchGetPentests() { return this.to('BatchGetPentests'); } /** * Grants permission to retrieve multiple security testing contents metadata in a single request * * Access Level: Read * * https://docs.aws.amazon.com/securityagent/API_BatchGetSecurityTestContentMetadata.html */ toBatchGetSecurityTestContentMetadata() { return this.to('BatchGetSecurityTestContentMetadata'); } /** * Grants permission to retrieve multiple security testing tasks in a single request * * Access Level: Read * * https://docs.aws.amazon.com/securityagent/API_BatchGetTasks.html */ toBatchGetTasks() { return this.to('BatchGetTasks'); } /** * Grants permission to create an agent instance record * * Access Level: Write * * https://docs.aws.amazon.com/securityagent/API_CreateAgentInstance.html */ toCreateAgentInstance() { return this.to('CreateAgentInstance'); } /** * Grants permission to create a new application * * Access Level: Write * * Dependent actions: * - iam:PassRole * - sso:CreateApplication * * https://docs.aws.amazon.com/securityagent/API_CreateApplication.html */ toCreateApplication() { return this.to('CreateApplication'); } /** * Grants permission to create a document review * * Access Level: Write * * https://docs.aws.amazon.com/securityagent/API_CreateDocumentReview.html */ toCreateDocumentReview() { return this.to('CreateDocumentReview'); } /** * Grants permission to create a security testing integration * * Access Level: Write * * https://docs.aws.amazon.com/securityagent/API_CreateIntegration.html */ toCreateIntegration() { return this.to('CreateIntegration'); } /** * Grants permission to add a single member to a agent instance with specified role * * Access Level: Write * * https://docs.aws.amazon.com/securityagent/API_CreateMembership.html */ toCreateMembership() { return this.to('CreateMembership'); } /** * Grants permission to create a one time login session * * Access Level: Write * * https://docs.aws.amazon.com/securityagent/API_CreateOneTimeLoginSession.html */ toCreateOneTimeLoginSession() { return this.to('CreateOneTimeLoginSession'); } /** * Grants permission to create a new penetration test configuration * * Access Level: Write * * https://docs.aws.amazon.com/securityagent/API_CreatePentest.html */ toCreatePentest() { return this.to('CreatePentest'); } /** * Grants permission to delete an agent instance record * * Access Level: Write * * https://docs.aws.amazon.com/securityagent/API_DeleteAgentInstance.html */ toDeleteAgentInstance() { return this.to('DeleteAgentInstance'); } /** * Grants permission to delete application * * Access Level: Write * * https://docs.aws.amazon.com/securityagent/API_DeleteApplication.html */ toDeleteApplication() { return this.to('DeleteApplication'); } /** * Grants permission to delete an Artifact * * Access Level: Write * * https://docs.aws.amazon.com/securityagent/API_DeleteArtifact.html */ toDeleteArtifact() { return this.to('DeleteArtifact'); } /** * Grants permission to delete a customer managed Control * * Access Level: Write * * https://docs.aws.amazon.com/securityagent/API_DeleteControl.html */ toDeleteControl() { return this.to('DeleteControl'); } /** * Grants permission to delete the integration of an application * * Access Level: Write * * https://docs.aws.amazon.com/securityagent/API_DeleteIntegration.html */ toDeleteIntegration() { return this.to('DeleteIntegration'); } /** * Grants permission to remove a single member associated to an agent instance * * Access Level: Write * * https://docs.aws.amazon.com/securityagent/API_DeleteMembership.html */ toDeleteMembership() { return this.to('DeleteMembership'); } /** * Grants permission to retrieve security findings for a penetration test or security testing tasks in a penetration test * * Access Level: Read * * https://docs.aws.amazon.com/securityagent/API_DescribeFindings.html */ toDescribeFindings() { return this.to('DescribeFindings'); } /** * Grants permission to get application details by application ID * * Access Level: Read * * https://docs.aws.amazon.com/securityagent/API_GetApplication.html */ toGetApplication() { return this.to('GetApplication'); } /** * Grants permission to retrieve an Artifact for the given Agent Instance * * Access Level: Read * * https://docs.aws.amazon.com/securityagent/API_GetArtifact.html */ toGetArtifact() { return this.to('GetArtifact'); } /** * Grants permission to retrieve a Code Review Task * * Access Level: Read * * https://docs.aws.amazon.com/securityagent/API_GetCodeReviewTask.html */ toGetCodeReviewTask() { return this.to('GetCodeReviewTask'); } /** * Grants permission to retrieve a Control * * Access Level: Read * * https://docs.aws.amazon.com/securityagent/API_GetControl.html */ toGetControl() { return this.to('GetControl'); } /** * Grants permission to retrieve a document review task * * Access Level: Read * * https://docs.aws.amazon.com/securityagent/API_GetDocReviewTask.html */ toGetDocReviewTask() { return this.to('GetDocReviewTask'); } /** * Grants permission to get the status of the associated agent instance document review * * Access Level: Read * * https://docs.aws.amazon.com/securityagent/API_GetDocumentReview.html */ toGetDocumentReview() { return this.to('GetDocumentReview'); } /** * Grants permission to get document review artifact for a specific document * * Access Level: Read * * https://docs.aws.amazon.com/securityagent/API_GetDocumentReviewArtifact.html */ toGetDocumentReviewArtifact() { return this.to('GetDocumentReviewArtifact'); } /** * Grants permission to get the integration metadata by ID * * Access Level: Read * * https://docs.aws.amazon.com/securityagent/API_GetIntegration.html */ toGetIntegration() { return this.to('GetIntegration'); } /** * Grants permission to retrieve credentials for a one time login session * * Access Level: Read * * https://docs.aws.amazon.com/securityagent/API_GetLoginSessionCredentials.html */ toGetLoginSessionCredentials() { return this.to('GetLoginSessionCredentials'); } /** * Grants permission to process and invalidate a one time login session * * Access Level: Write * * https://docs.aws.amazon.com/securityagent/API_HandleOneTimeLoginSession.html */ toHandleOneTimeLoginSession() { return this.to('HandleOneTimeLoginSession'); } /** * Grants permission to initiate the registration of Security Agent App for the given provider (eg: GitHub) * * Access Level: Write * * https://docs.aws.amazon.com/securityagent/API_InitiateProviderRegistration.html */ toInitiateProviderRegistration() { return this.to('InitiateProviderRegistration'); } /** * Grants permission to list tasks for a specific agent instance * * Access Level: List * * https://docs.aws.amazon.com/securityagent/API_ListAgentInstanceTasks.html */ toListAgentInstanceTasks() { return this.to('ListAgentInstanceTasks'); } /** * Grants permission to list agent instances * * Access Level: List * * https://docs.aws.amazon.com/securityagent/API_ListAgentInstances.html */ toListAgentInstances() { return this.to('ListAgentInstances'); } /** * Grants permission to list all applications in the account * * Access Level: List * * https://docs.aws.amazon.com/securityagent/API_ListApplications.html */ toListApplications() { return this.to('ListApplications'); } /** * Grants permission to list all artifacts for the given project * * Access Level: List * * https://docs.aws.amazon.com/securityagent/API_ListArtifacts.html */ toListArtifacts() { return this.to('ListArtifacts'); } /** * Grants permission to list all Controls * * Access Level: List * * https://docs.aws.amazon.com/securityagent/API_ListControls.html */ toListControls() { return this.to('ListControls'); } /** * Grants permission to list discovered endpoints associated with a pentest job with optional URI prefix filtering * * Access Level: List * * https://docs.aws.amazon.com/securityagent/API_ListDiscoveredEndpoints.html */ toListDiscoveredEndpoints() { return this.to('ListDiscoveredEndpoints'); } /** * Grants permission to list document review comments * * Access Level: List * * https://docs.aws.amazon.com/securityagent/API_ListDocumentReviewComments.html */ toListDocumentReviewComments() { return this.to('ListDocumentReviewComments'); } /** * Grants permission to list all document reviews for the given project * * Access Level: List * * https://docs.aws.amazon.com/securityagent/API_ListDocumentReviews.html */ toListDocumentReviews() { return this.to('ListDocumentReviews'); } /** * Grants permission to list findings with filtering and pagination support * * Access Level: List * * https://docs.aws.amazon.com/securityagent/API_ListFindings.html */ toListFindings() { return this.to('ListFindings'); } /** * Grants permission to list integrated resources for an agent instance * * Access Level: List * * https://docs.aws.amazon.com/securityagent/API_ListIntegratedResources.html */ toListIntegratedResources() { return this.to('ListIntegratedResources'); } /** * Grants permission to get the integrations owned by the caller's AWS account * * Access Level: List * * https://docs.aws.amazon.com/securityagent/API_ListIntegrations.html */ toListIntegrations() { return this.to('ListIntegrations'); } /** * Grants permission to list all members associated to an agent instance with pagination support * * Access Level: List * * https://docs.aws.amazon.com/securityagent/API_ListMemberships.html */ toListMemberships() { return this.to('ListMemberships'); } /** * Grants permission to list penetration test jobs associated with a penetration test * * Access Level: List * * https://docs.aws.amazon.com/securityagent/API_ListPentestJobsForPentest.html */ toListPentestJobsForPentest() { return this.to('ListPentestJobsForPentest'); } /** * Grants permission to list penetration tests with optional filtering by status * * Access Level: List * * https://docs.aws.amazon.com/securityagent/API_ListPentests.html */ toListPentests() { return this.to('ListPentests'); } /** * Grants permission to list resources from Integration * * Access Level: List * * https://docs.aws.amazon.com/securityagent/API_ListResourcesFromIntegration.html */ toListResourcesFromIntegration() { return this.to('ListResourcesFromIntegration'); } /** * Grants permission to list security testing tasks associated with a pentest job * * Access Level: List * * https://docs.aws.amazon.com/securityagent/API_ListTasks.html */ toListTasks() { return this.to('ListTasks'); } /** * Grants permission to start code remediation for the findings * * Access Level: Write * * https://docs.aws.amazon.com/securityagent/API_StartCodeRemediation.html */ toStartCodeRemediation() { return this.to('StartCodeRemediation'); } /** * Grants permission to initiate the execution of a penetration test * * Access Level: Write * * https://docs.aws.amazon.com/securityagent/API_StartPentestExecution.html */ toStartPentestExecution() { return this.to('StartPentestExecution'); } /** * Grants permission to stop the execution of a running penetration test * * Access Level: Write * * https://docs.aws.amazon.com/securityagent/API_StopPentestExecution.html */ toStopPentestExecution() { return this.to('StopPentestExecution'); } /** * Grants permission to toggle the status * * Access Level: Write * * https://docs.aws.amazon.com/securityagent/API_ToggleManagedControl.html */ toToggleManagedControl() { return this.to('ToggleManagedControl'); } /** * Grants permission to update an agent instance record * * Access Level: Write * * https://docs.aws.amazon.com/securityagent/API_UpdateAgentInstance.html */ toUpdateAgentInstance() { return this.to('UpdateAgentInstance'); } /** * Grants permission to update application configuration * * Access Level: Write * * Dependent actions: * - iam:PassRole * * https://docs.aws.amazon.com/securityagent/API_UpdateApplication.html */ toUpdateApplication() { return this.to('UpdateApplication'); } /** * Grants permission to update a customer managed Control * * Access Level: Write * * https://docs.aws.amazon.com/securityagent/API_UpdateControl.html */ toUpdateControl() { return this.to('UpdateControl'); } /** * Grants permission to update an existing security finding with new details or status * * Access Level: Write * * https://docs.aws.amazon.com/securityagent/API_UpdateFinding.html */ toUpdateFinding() { return this.to('UpdateFinding'); } /** * Grants permission to update integrated resources for an agent instance * * Access Level: Write * * https://docs.aws.amazon.com/securityagent/API_UpdateIntegratedResources.html */ toUpdateIntegratedResources() { return this.to('UpdateIntegratedResources'); } /** * Grants permission to update an existing penetration test with new configuration or settings * * Access Level: Write * * https://docs.aws.amazon.com/securityagent/API_UpdatePentest.html */ toUpdatePentest() { return this.to('UpdatePentest'); } /** * Grants permission to verify ownership for a registered target domain in an agent instance * * Access Level: Write * * https://docs.aws.amazon.com/securityagent/API_VerifyTargetDomain.html */ toVerifyTargetDomain() { return this.to('VerifyTargetDomain'); } /** * Adds a resource of type Application to the statement * * https://docs.aws.amazon.com/securityagent/latest/userguide/auth-and-access-control-iam-access-control-identity-based.html#arn-formats * * @param applicationId - Identifier for the applicationId. * @param account - Account of the resource; defaults to `*`, unless using the CDK, where the default is the current Stack's account. * @param region - Region of the resource; defaults to `*`, unless using the CDK, where the default is the current Stack's region. * @param partition - Partition of the AWS account [aws, aws-cn, aws-us-gov]; defaults to `aws`, unless using the CDK, where the default is the current Stack's partition. */ onApplication(applicationId, account, region, partition) { return this.on(`arn:${partition ?? this.defaultPartition}:securityagent:${region ?? this.defaultRegion}:${account ?? this.defaultAccount}:application/${applicationId}`); } /** * Adds a resource of type Control to the statement * * https://docs.aws.amazon.com/securityagent/latest/userguide/auth-and-access-control-iam-access-control-identity-based.html#arn-formats * * @param controlId - Identifier for the controlId. * @param account - Account of the resource; defaults to `*`, unless using the CDK, where the default is the current Stack's account. * @param region - Region of the resource; defaults to `*`, unless using the CDK, where the default is the current Stack's region. * @param partition - Partition of the AWS account [aws, aws-cn, aws-us-gov]; defaults to `aws`, unless using the CDK, where the default is the current Stack's partition. */ onControl(controlId, account, region, partition) { return this.on(`arn:${partition ?? this.defaultPartition}:securityagent:${region ?? this.defaultRegion}:${account ?? this.defaultAccount}:control/${controlId}`); } /** * Adds a resource of type Integration to the statement * * https://docs.aws.amazon.com/securityagent/latest/userguide/auth-and-access-control-iam-access-control-identity-based.html#arn-formats * * @param integrationId - Identifier for the integrationId. * @param account - Account of the resource; defaults to `*`, unless using the CDK, where the default is the current Stack's account. * @param region - Region of the resource; defaults to `*`, unless using the CDK, where the default is the current Stack's region. * @param partition - Partition of the AWS account [aws, aws-cn, aws-us-gov]; defaults to `aws`, unless using the CDK, where the default is the current Stack's partition. */ onIntegration(integrationId, account, region, partition) { return this.on(`arn:${partition ?? this.defaultPartition}:securityagent:${region ?? this.defaultRegion}:${account ?? this.defaultAccount}:integration/${integrationId}`); } /** * Adds a resource of type AgentInstance to the statement * * https://docs.aws.amazon.com/securityagent/latest/userguide/auth-and-access-control-iam-access-control-identity-based.html#arn-formats * * @param agentId - Identifier for the agentId. * @param account - Account of the resource; defaults to `*`, unless using the CDK, where the default is the current Stack's account. * @param region - Region of the resource; defaults to `*`, unless using the CDK, where the default is the current Stack's region. * @param partition - Partition of the AWS account [aws, aws-cn, aws-us-gov]; defaults to `aws`, unless using the CDK, where the default is the current Stack's partition. */ onAgentInstance(agentId, account, region, partition) { return this.on(`arn:${partition ?? this.defaultPartition}:securityagent:${region ?? this.defaultRegion}:${account ?? this.defaultAccount}:agent-instance/${agentId}`); } /** * Adds a resource of type Artifact to the statement * * https://docs.aws.amazon.com/securityagent/latest/userguide/auth-and-access-control-iam-access-control-identity-based.html#arn-formats * * @param agentId - Identifier for the agentId. * @param artifactId - Identifier for the artifactId. * @param account - Account of the resource; defaults to `*`, unless using the CDK, where the default is the current Stack's account. * @param region - Region of the resource; defaults to `*`, unless using the CDK, where the default is the current Stack's region. * @param partition - Partition of the AWS account [aws, aws-cn, aws-us-gov]; defaults to `aws`, unless using the CDK, where the default is the current Stack's partition. */ onArtifact(agentId, artifactId, account, region, partition) { return this.on(`arn:${partition ?? this.defaultPartition}:securityagent:${region ?? this.defaultRegion}:${account ?? this.defaultAccount}:agent-instance/${agentId}/artifact/${artifactId}`); } /** * Adds a resource of type Pentest to the statement * * https://docs.aws.amazon.com/securityagent/latest/userguide/auth-and-access-control-iam-access-control-identity-based.html#arn-formats * * @param agentId - Identifier for the agentId. * @param pentestId - Identifier for the pentestId. * @param account - Account of the resource; defaults to `*`, unless using the CDK, where the default is the current Stack's account. * @param region - Region of the resource; defaults to `*`, unless using the CDK, where the default is the current Stack's region. * @param partition - Partition of the AWS account [aws, aws-cn, aws-us-gov]; defaults to `aws`, unless using the CDK, where the default is the current Stack's partition. */ onPentest(agentId, pentestId, account, region, partition) { return this.on(`arn:${partition ?? this.defaultPartition}:securityagent:${region ?? this.defaultRegion}:${account ?? this.defaultAccount}:agent-instance/${agentId}/pentest/${pentestId}`); } /** * Adds a resource of type PentestJob to the statement * * https://docs.aws.amazon.com/securityagent/latest/userguide/auth-and-access-control-iam-access-control-identity-based.html#arn-formats * * @param agentId - Identifier for the agentId. * @param jobId - Identifier for the jobId. * @param account - Account of the resource; defaults to `*`, unless using the CDK, where the default is the current Stack's account. * @param region - Region of the resource; defaults to `*`, unless using the CDK, where the default is the current Stack's region. * @param partition - Partition of the AWS account [aws, aws-cn, aws-us-gov]; defaults to `aws`, unless using the CDK, where the default is the current Stack's partition. */ onPentestJob(agentId, jobId, account, region, partition) { return this.on(`arn:${partition ?? this.defaultPartition}:securityagent:${region ?? this.defaultRegion}:${account ?? this.defaultAccount}:agent-instance/${agentId}/pentest-job/${jobId}`); } /** * Adds a resource of type PentestTask to the statement * * https://docs.aws.amazon.com/securityagent/latest/userguide/auth-and-access-control-iam-access-control-identity-based.html#arn-formats * * @param agentId - Identifier for the agentId. * @param taskId - Identifier for the taskId. * @param account - Account of the resource; defaults to `*`, unless using the CDK, where the default is the current Stack's account. * @param region - Region of the resource; defaults to `*`, unless using the CDK, where the default is the current Stack's region. * @param partition - Partition of the AWS account [aws, aws-cn, aws-us-gov]; defaults to `aws`, unless using the CDK, where the default is the current Stack's partition. */ onPentestTask(agentId, taskId, account, region, partition) { return this.on(`arn:${partition ?? this.defaultPartition}:securityagent:${region ?? this.defaultRegion}:${account ?? this.defaultAccount}:agent-instance/${agentId}/pentest-task/${taskId}`); } /** * Adds a resource of type Finding to the statement * * https://docs.aws.amazon.com/securityagent/latest/userguide/auth-and-access-control-iam-access-control-identity-based.html#arn-formats * * @param agentId - Identifier for the agentId. * @param findingId - Identifier for the findingId. * @param account - Account of the resource; defaults to `*`, unless using the CDK, where the default is the current Stack's account. * @param region - Region of the resource; defaults to `*`, unless using the CDK, where the default is the current Stack's region. * @param partition - Partition of the AWS account [aws, aws-cn, aws-us-gov]; defaults to `aws`, unless using the CDK, where the default is the current Stack's partition. */ onFinding(agentId, findingId, account, region, partition) { return this.on(`arn:${partition ?? this.defaultPartition}:securityagent:${region ?? this.defaultRegion}:${account ?? this.defaultAccount}:agent-instance/${agentId}/finding/${findingId}`); } } exports.Securityagent = Securityagent; //# sourceMappingURL=data:application/json;base64,