azure-rbac-role-assignment-condition

Role-assignment conditions and descriptions may reveal principal identifiers, resource selectors, and operator-entered text.

azurehigh service: azure:rbac emits ContainsSecret

Where it sits

locationMicrosoft.Authorization/roleAssignments.properties.{principalId,condition,conditionVersion,description}
location kindpolicy_document
data kindssensitive_data
emits edgeContainsSecret
serviceAzure RBAC (Authorization) (azure:rbac)

Collection recipe

access moderead_api
operationRole Assignments - Get
response pathproperties.{principalId,condition,conditionVersion,description}
encodingjson
params{"resource_id": "\u003cazure-resource-id\u003e"}

Required permissions

Microsoft.Authorization/roleAssignments/read

References

move · open · esc close