需求:
只对oss目录有上传权限,不能预览,下载,删除
效果:
无法预览:
无法下载:
无法删除:
可以在指定目录上传:
策略:
{
"Version": "1",
"Statement": [
{
"Effect": "Allow", #allow代表允许
"Action": [
"oss:ListBuckets",
"oss:GetBucketStat",
"oss:GetBucketInfo",
"oss:GetBucketTagging",
"oss:GetBucketLifecycle",
"oss:GetBucketWorm",
"oss:GetBucketVersioning",
"oss:GetBucketAcl"
],
"Resource": "acs:oss:*:*:*"
},
{
"Effect": "Allow",
"Action": [
"oss:ListObjects",
"oss:GetBucketAcl"
],
"Resource": "acs:oss:*:*:bucket-name" #bucket-name是你的bucket的名字
},
{
"Effect": "Allow",
"Action": [
"oss:ListBuckets",
"oss:GetBucketStat",
"oss:GetBucketInfo",
"oss:GetBucketTagging",
"oss:GetBucketLifecycle",
"oss:GetBucketWorm",
"oss:GetBucketVersioning",
"oss:GetBucketAcl",
"oss:PutObject"
],
"Resource": "acs:oss:*:*:bucket-name/oss/*" #允许查看的目录
}
]
}