The cannot redeploy the application code (e.g. adding a new component type), but they can publish a new version of a survey (reworded and reordered questions, change of titles).
Is it accurate that in this case, the 'public' bucket serves a similar role as a 'edge router' in a traditional server architecture? I.e., completing the handshake with the public encrypted end user credentials confirms user role and subsequently provides user application access according to assigned permissions?
normally I think of edge servers as terminating an SSL (HTTPS) connection nearer the user. So encryption is used, but not tied to a user usually. Also the idea of edge servers is you have lots of them, so traffic is terminated near the user, we do not multiple regions, except that many of our underlying AWS resources are already multi region.
I feel like our public buckets provide credentials that allow user to initialize and authenticated session with auth-server. I would still say AWS is running the auth-server though (IAM).
Where has this description come from? Is this for a security review?