aws-sts-external-id-request-parameter

ExternalId is a customer-supplied trust nonce and can be exposed in callers, traces, or request logging even though AWS does not treat it as a password.

awsmedium service: aws:sts emits ContainsCredential

Where it sits

locationAssumeRole request.ExternalId
location kindconfig_field
data kindscredential sensitive_data
emits edgeContainsCredential
serviceSTS (aws:sts)

Collection recipe

access modecreation_response_only
operationAssumeRole
response pathrequest.ExternalId
encodingstring
params{"ExternalId": "\u003cexternal-id\u003e", "RoleArn": "\u003crole-arn\u003e"}

Required permissions

sts:AssumeRole

References

move · open · esc close