I need an Amazon S3 policy that will allow Cloudfront and my website access to get/put objects but to prevent direct linking to objects outside of that. Policy must also be compatible with this Wordpress plugin that offloads assets to same S3 bucket - [login to view URL]