gcp-pubsub-pulled-message-data

Pub/Sub messages can transport plaintext credentials or arbitrary sensitive payloads.

gcpcritical service: gcp:pubsub emits CanReadData

Where it sits

locationpubsub.projects.subscriptions.pull.receivedMessages[].message.data
location kindmessage_body
data kindscredential customer_data pii sensitive_data
emits edgeCanReadData
servicePub/Sub (gcp:pubsub)

Collection recipe

access moderead_api
operationpubsub.projects.subscriptions.pull
response pathreceivedMessages[].message.data
encodingbase64
params{"maxMessages": "\u003ccount\u003e", "subscription": "projects/\u003cproject\u003e/subscriptions/\u003csubscription\u003e"}

Required permissions

pubsub.subscriptions.consume

References

move · open · esc close