1. Context
A. Assignment context
HookB develops several software ideas, prototypes and beta products simultaneously. During R&D, these resources may contain unreleased concepts, documentation, test interfaces and technical information.
For this assignment, the fictional internal R&D solution is called Project Aegis. Your task is to research and propose how HookB can protect Aegis and later reuse the same architecture for other projects.
B. More context — what are we trying to protect?
You do not need to know AWS before starting this assignment. The purpose is to learn the relevant AWS building blocks, understand what each one does, and then decide how they could work together.
Imagine HookB is developing several unreleased products at the same time. For each product there may be documentation, an HTML prototype, a beta application, screenshots, test data and internal notes. Today it is easy to upload an HTML page to S3 and share a CloudFront link. The problem is that anyone who receives that link may be able to forward it to somebody else.
We need a reusable protection layer. A known team member might sign in and retain access until we revoke it. A temporary tester might instead receive a one-time invitation that can only be redeemed once and expires if unused. After redemption, the tester should receive a temporary session so the website works normally for a limited period. When that session expires, access must stop. Simply knowing the URL must never be enough.
Your research should therefore answer three beginner-level questions first: Who is the visitor? (authentication), what is that visitor allowed to see? (authorization), and how does AWS safely deliver the private files? Only after understanding those three questions should you design the complete flow.
Start with these AWS resources
- Amazon Cognito — What is Amazon Cognito?
- Amazon S3 — Blocking public access
- CloudFront — Restrict access to an S3 origin with OAC
- Amazon S3 — Presigned URLs
- CloudFront — Serving private content with signed URLs/cookies
- AWS Lambda — Developer Guide
- Amazon DynamoDB — Introduction
- AWS IAM — Security best practices
Do not assume every service above belongs in the final solution. Part of the assignment is determining which services are necessary, which overlap, and what the simplest secure first version should be.
Je hoeft AWS nog niet te kennen voordat je met deze opdracht begint. Het doel is juist om de relevante AWS-bouwstenen te leren kennen, te begrijpen wat elke dienst doet en daarna te bepalen hoe ze samen kunnen werken.
Stel je voor dat HookB meerdere nog niet uitgebrachte producten tegelijk ontwikkelt. Per product kunnen er documentatie, een HTML-prototype, een bèta-applicatie, screenshots, testdata en interne notities bestaan. Een HTML-pagina op S3 plaatsen en een CloudFront-link delen is eenvoudig. Het probleem is dat iemand die de link ontvangt deze mogelijk naar anderen kan doorsturen.
We hebben daarom een herbruikbare beveiligingslaag nodig. Een bekend teamlid kan bijvoorbeeld inloggen en toegang behouden totdat wij die intrekken. Een tijdelijke tester kan in plaats daarvan een eenmalige uitnodiging ontvangen die slechts één keer kan worden ingewisseld en vervalt als deze niet op tijd wordt gebruikt. Na het inwisselen moet de tester een tijdelijke sessie krijgen zodat de website gedurende een beperkte periode normaal werkt. Zodra die sessie verloopt, moet de toegang stoppen. Alleen de URL kennen mag nooit voldoende zijn.
Begin je onderzoek daarom met drie basisvragen: Wie is de bezoeker? (authenticatie), wat mag deze bezoeker bekijken? (autorisatie), en hoe levert AWS de privébestanden veilig aan? Pas nadat je deze drie onderdelen begrijpt, ontwerp je de volledige flow.
Begin met deze AWS-bronnen
- Amazon Cognito — What is Amazon Cognito?
- Amazon S3 — Block Public Access
- CloudFront — S3-origin beveiligen met OAC
- Amazon S3 — Presigned URLs
- CloudFront — Private content met signed URLs/cookies
- AWS Lambda — Developer Guide
- Amazon DynamoDB — Introduction
- AWS IAM — Security best practices
Ga er niet vanuit dat elke bovenstaande dienst in de uiteindelijke oplossing moet komen. Een deel van de opdracht is bepalen welke diensten nodig zijn, waar functies elkaar overlappen en wat de eenvoudigste veilige eerste versie is.
2. Proposed content structure
The project may contain different protected areas:
Important: the folder name protected is only an organizational convention. It is not itself a security control.
3. Required access models
Authenticated users
Known team members or recurring testers authenticate using Amazon Cognito or another justified AWS mechanism. Permissions should determine which project and which areas they may access.
Temporary testers
A tester without a permanent account receives a single-use invitation/code. The invitation expires, becomes unusable after successful redemption, and creates only a short-lived authorized session.
docs and prototype, but not beta. User B may access only beta. A forwarded URL should not bypass these permissions.4. Research questions
Amazon Cognito
What does Cognito provide for authentication, users, sessions, MFA/OTP and tokens? What does it not provide for our proposed single-use invitation workflow?
S3 vs CloudFront
Why should the S3 content remain private? Compare direct S3 presigned URLs with serving a protected website through CloudFront.
One-time invitations
Design a method for generating, storing, validating, redeeming and revoking one-time invitation codes. Consider Lambda and DynamoDB. Should codes be stored as plaintext or hashes?
Temporary sessions
After a code is redeemed, how should a tester receive access for 15 minutes, 1 hour, 24 hours or another configured period without entering a code for every HTML, CSS, JS or image request?
Authorization
How can the system enforce project-level and area-level permissions such as Aegis/docs versus Aegis/beta?
Audit & revocation
What should be logged? How can HookB revoke a user's access, invalidate an invitation, or terminate future access after a project is closed?
5. Security checklist
Evaluate whether your proposed design satisfies each requirement.
6. Threat scenarios
Explain what your architecture does in each case.
Shared link
A tester sends the Aegis beta URL to a friend.
Reused invitation
Someone attempts to redeem an already-used access code.
Expired access
A tester returns after the temporary session has expired.
Direct S3 attempt
Someone discovers the underlying S3 object path.
Unauthorized area
A docs-only user manually changes the URL to /beta/.
Leaked code
An invitation code is exposed before the intended tester uses it.
7. Required deliverables
8. Design constraint
This is an R&D protection system for multiple small projects. Security matters, but the proposed solution should remain practical, low-cost and reusable.
Your recommendation should clearly identify which controls are essential for the first version and which can be introduced later.
9. Final recommendation
At the end of the research, provide your recommended request flow. For example, determine whether the final design should resemble:
Do not simply copy this example. Research whether it is technically correct, identify the AWS components needed, and propose your own final architecture.
10. Completion
Chantal Nicasia
Date completed: __________________
HookB SMB Solutions
Reviewed: _______________________