PutObjectAcl
Applies or updates an ACL on an object, customizing access rights at the object level.
Stored Procedure-Specific Information
This procedure applies an ACL to an object identified by the Bucket and Key inputs. As with bucket ACLs, you can supply a canned ACL through the ACL input or the individual grant inputs (GrantFullControl, GrantRead, GrantReadAcp, GrantWrite, and GrantWriteAcp), or supply a full AccessControlPolicy XML document. If the bucket has versioning enabled, set VersionId to target a specific version of the object.The following example grants public read access to an object:
EXECUTE PutObjectAcl
@Bucket='BucketName',
@Key='ObjectName',
@ACL='public-read'
Input
| Name | Type | Required | Description |
| Bucket | String | True | The name of the S3 bucket that contains the object for which the ACL will be applied. |
| Key | String | True | The key (name) of the object targeted by the PUT ACL operation. |
| AccessControlPolicy | String | False | The XML structure that defines the access control policy, including grants and grantees, to apply to the object. |
| VersionId | String | False | If versioning is enabled on the bucket, specifies the version of the object to apply the ACL to. |
| ACL | String | False | A predefined (canned) ACL setting, such as private, public-read, or authenticated-read, to quickly configure access permissions for the object. |
| GrantFullControl | String | False | Grants the specified AWS account full control over the object, including read, write, read ACL, and write ACL permissions. |
| GrantRead | String | False | Grants the specified AWS account permission to read the object's data and metadata. |
| GrantReadAcp | String | False | Grants the specified AWS account permission to read the ACL of the object. |
| GrantWrite | String | False | Grants the specified AWS account permission to write or overwrite the object's data. |
| GrantWriteAcp | String | False | Grants the specified AWS account permission to write or modify the ACL of the object. |
| ExpectedBucketOwner | String | False | The AWS account ID expected to own the bucket. The request fails if the actual owner does not match. |
Result Set Columns
| Name | Type | Description |
| Status | String | Indicates the result of the ACL update operation, such as success or failure. |