gcp-iap-iap-settings-client-secret-input
IAP access settings can carry application and workforce OAuth client secrets as input-only plaintext fields.
Where it sits
| location | iap.updateIapSettings.request.accessSettings.{oauthSettings.clientSecret,workforceIdentitySettings.oauth2.clientSecret} |
|---|---|
| location kind | secret_value |
| data kinds | oauth_token secret_key credential |
| emits edge | ContainsCredential |
| service | Identity-Aware Proxy (gcp:iap) |
Collection recipe
| access mode | write_only_input |
|---|---|
| operation | iap.updateIapSettings |
| response path | request.accessSettings.{oauthSettings.clientSecret,workforceIdentitySettings.oauth2.clientSecret} |
| encoding | json |
| params | {"name": "\u003cresource-name\u003e"} |
Required permissions
iap.folders.updateSettings iap.organizations.updateSettings iap.projects.updateSettings iap.web.updateSettings iap.webServices.updateSettings iap.webServiceVersions.updateSettings iap.webTypes.updateSettings