gcp-iap-iap-settings-client-secret-input

IAP access settings can carry application and workforce OAuth client secrets as input-only plaintext fields.

gcpcritical service: gcp:iap emits ContainsCredential

Where it sits

locationiap.updateIapSettings.request.accessSettings.{oauthSettings.clientSecret,workforceIdentitySettings.oauth2.clientSecret}
location kindsecret_value
data kindsoauth_token secret_key credential
emits edgeContainsCredential
serviceIdentity-Aware Proxy (gcp:iap)

Collection recipe

access modewrite_only_input
operationiap.updateIapSettings
response pathrequest.accessSettings.{oauthSettings.clientSecret,workforceIdentitySettings.oauth2.clientSecret}
encodingjson
params{"name": "\u003cresource-name\u003e"}

Required permissions

iap.folders.updateSettings
iap.organizations.updateSettings
iap.projects.updateSettings
iap.web.updateSettings
iap.webServices.updateSettings
iap.webServiceVersions.updateSettings
iap.webTypes.updateSettings

References

move · open · esc close