azure-adls-sas-token

SAS-bearing ADLS URLs are plaintext delegated credentials commonly persisted in jobs and logs. No single Azure RBAC action authorizes this service-native path; its own authentication and authorization apply.

azurecritical service: azure:adls emits ExposesCredential

Where it sits

locationBlob service SAS/account SAS/user delegation SAS URI query
location kindconnection_string
data kindscredential session_token signing_secret
emits edgeExposesCredential
serviceData Lake Storage Gen2 (azure:adls)

Collection recipe

access modedata_plane
operationSAS token supplied to Path REST API
response pathrequest URI query
encodingurl_encoded
params{"resource_id": "\u003cazure-resource-id\u003e"}

References

move · open · esc close