ReadonlyallowOptional ReadonlycrossBucket-level grant for cross-account roles. These cannot be matched by the aws:userId
condition on allowStatement because their role IDs are not resolvable from the
deploying account, so they are granted by ARN principal instead. Undefined when no
cross-account role was supplied.
ReadonlydenyAll bucket-level allow statements which should be added to the bucket policy. Prefer this over reading allowStatement directly, so that the cross-account grant is not dropped.
Helper class for generating bucket policy statements which allow or deny access to an entire bucket. Used to create bucket-level default deny statements to block accesses not granted in the bucket policy.