shinyapps io bucket policy for https S3 access

I'm looking at enabling https access for S3 from my hosted app

Is the address list on correct for this?

Currently I'm using a bucket policy like

    "Version": "2012-10-17",
    "Statement": [
            "Effect": "Allow",
            "Principal": "*",
            "Action": "s3:GetObject",
            "Resource": "arn:aws:s3:::example-bucket-data/*",
            "Condition": {
                "IpAddress": {
                    "aws:SourceIp": [

but I'm seeing 403 Forbidden currently... If I add my own address to that IP list it does seem to enable http download, so I think this is close to being correct...

It's late now - I'm probably just doing something obvious wrong.. will try again tomorrow!