Enhance SCP to Cover Additional BlockPublicAccess Cases @petabook (#69)
This update extends the Service Control Policy (SCP) to address more scenarios involving S3 `BlockPublicAccess`. * There are two types of `BlockPublicAccess` APIs: - Bucket-level - Account-levelBy using a wildcard * the SCP now denies both (and future) types.
- Additionally, deletion of these policies is protected to prevent accidental or unauthorized removal.
Impact
- Strengthens security posture by ensuring consistent enforcement of S3 BlockPublicAccess at both the bucket and account levels.
- Prevents tampering or removal of critical access control policies.