# Uppy with companion upload to s3, the file is 403 when try to access it from backend

**URL:** <https://community.transloadit.com/t/uppy-with-companion-upload-to-s3-the-file-is-403-when-try-to-access-it-from-backend/16463>\
**Category:** Uppy\
**Created:** [February 8, 2023, 7:56am UTC](https://community.transloadit.com/t/uppy-with-companion-upload-to-s3-the-file-is-403-when-try-to-access-it-from-backend/16463 "2023-02-08T07:56:15Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rashe](https://yyz2.discourse-cdn.com/flex032/user_avatar/community.transloadit.com/rashe/32/777_2.png) [@Rashe](https://community.transloadit.com/u/Rashe)\
**Post date:** [February 8, 2023, 7:56am UTC](https://community.transloadit.com/t/uppy-with-companion-upload-to-s3-the-file-is-403-when-try-to-access-it-from-backend/16463/1 "2023-02-08T07:56:15Z")

</div>

The problem:  
Cannot download file in backend from cloudfront or s3 after uploading it with uppy, but only for Instagram uploads

**Providers** :

- Manual upload
- Instagram

**It works for Manual Upload**  
**It doesn’t work for Instagram**

Companion code:

```auto
{
      providerOptions: {
        instagram: {
          key: process.env.instagram_basic_display_appId,
          secret: process.env.instagram_basic_display_appSecret,
        },
      },
      s3: {
        getKey: (req: any, filename: string) => `${ Date.now() }-${ filename }`,
        key: process.env.AWS_ACCESS_KEY_ID,
        secret: process.env.AWS_SECRET_ACCESS_KEY,
        bucket: "BUCKET_NAME",
        region: "us-east-1",
        expires: 30000,
        acl: "public-read",
      },
      server: {
        host: process.env.companion_server_host,
        protocol: "https",
        path:uppyCompanionUrl,
      },
      debug: false,
      filePath: ".",
      uploadUrls: [/^http:\/\/comain.com\//, /^http:\/\/localhost\//, /^https:\/\/app-dev.domain.com\//, /^https:\/\/BUCKET_NAME.amazonaws.com\//, /^https:\/\/amazonaws.com\//, /^https:\/\/s3.us-east-1.amazonaws.com\//],
      secret: process.env.companion_secret,
      corsOrigins:corsWhiteList,
      streamingUpload: true,
      allowLocalUrls: true,
      maxFileSize: 100000000,
      periodicPingInterval: 60000,
      periodicPingStaticPayload: {static: "payload"},
    }

```

Both manual and instagram uploads are through companion.

Any ideas why it doesn’t work for inta?

---

<div class="post-metadata">

**Author:** ![mifi](https://yyz2.discourse-cdn.com/flex032/user_avatar/community.transloadit.com/mifi/32/603_2.png) [@mifi](https://community.transloadit.com/u/mifi)\
**Post date:** [February 8, 2023, 8:26am UTC](https://community.transloadit.com/t/uppy-with-companion-upload-to-s3-the-file-is-403-when-try-to-access-it-from-backend/16463/2 "2023-02-08T08:26:50Z")

</div>

Have you tried without ACLs? and disable ACL on your bucket

---

<div class="post-metadata">

**Author:** ![Rashe](https://yyz2.discourse-cdn.com/flex032/user_avatar/community.transloadit.com/rashe/32/777_2.png) [@Rashe](https://community.transloadit.com/u/Rashe)\
**Post date:** [February 8, 2023, 9:13am UTC](https://community.transloadit.com/t/uppy-with-companion-upload-to-s3-the-file-is-403-when-try-to-access-it-from-backend/16463/3 "2023-02-08T09:13:00Z")

</div>

Yes, the companion default ACL is “private”. Now it’s not accessible at all 🙂

---

<div class="post-metadata">

**Author:** ![mifi](https://yyz2.discourse-cdn.com/flex032/user_avatar/community.transloadit.com/mifi/32/603_2.png) [@mifi](https://community.transloadit.com/u/mifi)\
**Post date:** [February 8, 2023, 9:26am UTC](https://community.transloadit.com/t/uppy-with-companion-upload-to-s3-the-file-is-403-when-try-to-access-it-from-backend/16463/4 "2023-02-08T09:26:27Z")

</div>

which verison of companion are you running? in newer versions of companion, the default acl is no longer set: [uppy/migration-guides.md at main · transloadit/uppy · GitHub](https://github.com/transloadit/uppy/blob/main/website/src/docs/migration-guides.md#default-to-no-acl-for-aws-s3)

what is your bucket’s acl configuration?

---

<div class="post-metadata">

**Author:** ![Rashe](https://yyz2.discourse-cdn.com/flex032/user_avatar/community.transloadit.com/rashe/32/777_2.png) [@Rashe](https://community.transloadit.com/u/Rashe)\
**Post date:** [February 8, 2023, 9:50am UTC](https://community.transloadit.com/t/uppy-with-companion-upload-to-s3-the-file-is-403-when-try-to-access-it-from-backend/16463/5 "2023-02-08T09:50:37Z")

</div>

The uppy companion version is 4.20

The ACL:

 ![Screenshot 2023-02-08 at 11.49.29](https://canada1.discourse-cdn.com/flex032/uploads/transloadit/original/1X/3249b802710b488bd0a435c02b61550eecac6ded.png)

---

<div class="post-metadata">

**Author:** ![mifi](https://yyz2.discourse-cdn.com/flex032/user_avatar/community.transloadit.com/mifi/32/603_2.png) [@mifi](https://community.transloadit.com/u/mifi)\
**Post date:** [February 8, 2023, 10:00am UTC](https://community.transloadit.com/t/uppy-with-companion-upload-to-s3-the-file-is-403-when-try-to-access-it-from-backend/16463/6 "2023-02-08T10:00:04Z")

</div>

i mean this:

 ![Screenshot 2023-02-08 at 17.59.47](https://canada1.discourse-cdn.com/flex032/uploads/transloadit/original/1X/99cdc2298d3306c933893b6176982a0a4c21b630.png)

---

<div class="post-metadata">

**Author:** ![Rashe](https://yyz2.discourse-cdn.com/flex032/user_avatar/community.transloadit.com/rashe/32/777_2.png) [@Rashe](https://community.transloadit.com/u/Rashe)\
**Post date:** [February 8, 2023, 11:53am UTC](https://community.transloadit.com/t/uppy-with-companion-upload-to-s3-the-file-is-403-when-try-to-access-it-from-backend/16463/7 "2023-02-08T11:53:32Z")

</div>

I need a bucket policy to make it work, right?

---

<div class="post-metadata">

**Author:** ![Rashe](https://yyz2.discourse-cdn.com/flex032/user_avatar/community.transloadit.com/rashe/32/777_2.png) [@Rashe](https://community.transloadit.com/u/Rashe)\
**Post date:** [February 8, 2023, 12:23pm UTC](https://community.transloadit.com/t/uppy-with-companion-upload-to-s3-the-file-is-403-when-try-to-access-it-from-backend/16463/8 "2023-02-08T12:23:25Z")

</div>

Anyway, it cannot be done by removing ACL from bucket.

Any thoughts why objects have different permissions for manual upload and instagram upload with the same settings?

---

<div class="post-metadata">

**Author:** ![mifi](https://yyz2.discourse-cdn.com/flex032/user_avatar/community.transloadit.com/mifi/32/603_2.png) [@mifi](https://community.transloadit.com/u/mifi)\
**Post date:** [February 8, 2023, 2:12pm UTC](https://community.transloadit.com/t/uppy-with-companion-upload-to-s3-the-file-is-403-when-try-to-access-it-from-backend/16463/9 "2023-02-08T14:12:26Z")

</div>

> [@Rashe](#):
>
> I need a bucket policy to make it work, right?

Yes, can I see your bucket policy?

You can try this policy:

```auto
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "Stmt1405592139000",
            "Effect": "Allow",
            "Principal": "*",
            "Action": "s3:GetObject",
            "Resource": [
                "arn:aws:s3:::bucketname/*",
                "arn:aws:s3:::bucketname"
            ]
        }
    ]
}

```

Manual upload works differently from instagram, that’s probably why. They run different code.
