gcp-loadbalancing-iap-client-secret-input

An IAP OAuth client secret is a write-only backend-service input and can leak through IaC state or request logging.

gcpcritical service: gcp:loadbalancing emits ContainsCredential

Where it sits

locationcompute.backendServices.insert/compute.backendServices.patch/compute.backendServices.update.request.iap.oauth2ClientSecret
location kindsecret_value
data kindsoauth_token secret_key credential
emits edgeContainsCredential
serviceCloud Load Balancing (gcp:loadbalancing)

Collection recipe

access modewrite_only_input
operationcompute.backendServices.insert/compute.backendServices.patch/compute.backendServices.update
response pathrequest.iap.oauth2ClientSecret
encodingstring
params{"name": "\u003cresource-name\u003e"}

Required permissions

compute.backendServices.create
compute.backendServices.update

References

move · open · esc close