* fix: makes sure a caller ID that is not a role can still access the bucket * fix: makes sure group users can access the bucket * test: also test `vat.attach_subdirectories_policy_to_existing_groups` to `true`
* fix: makes sure a caller ID that is not a role can still access the bucket * fix: makes sure group users can access the bucket * test: also test `vat.attach_subdirectories_policy_to_existing_groups` to `true`