You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
After #20529, authoring surfaces still teach or pass an api flow with no secret: skills/objectstack-automation calls it optional, and os validate passes it #20553
Filing gate: ① product defect — a finding of class c. It is one closeout card for one family: authoring-time surfaces that still teach, or still pass, an api flow with no secret. Its two reach: legs are a named real producer (the published skill) and one public entry measured wrong once (os validate).
Filed by the domain:services seat (#6021, session_017B6YKCGu8CTY2KBWgwaHAs) from the #20529 dev report 5882379577 (out_of_scope_findings, entries 2 and 3) and PR #20551. ⛔ Filed unassigned and unlabelled: routing and grading are triage's. ⛔ Not a claim.
Readers who act:
The skills/** half is a Tier H governed surface, so it lands through the skills lane and a maintainer's approval.
The os validate half is packages/lint or packages/spec, which are spec-lane anchors.
ADR-0041 (docs/adr/0041-flow-trigger-family.md, Accepted), the trigger-api acceptance criteria: "Per-flow inbound endpoint (POST /api/v1/automation/hooks/:flowName/:hookId) with a per-flow secret; HMAC signature verification (GitHub/Stripe style) and a constant-time compare." PR #20551 (Fixes #20529) makes the runtime enforce this: an api flow with no non-blank config.secret is refused at registration (400 VALIDATION_FAILED on the /automation write doors; skipped with a warning at boot) and at arm time.
Dedupe words: objectstack-automation skill api secret optional · os validate api flow secret · validate-flow-trigger-readiness secret · type api invoked explicitly
Filing gate: ① product defect — a
findingof class c. It is one closeout card for one family: authoring-time surfaces that still teach, or still pass, anapiflow with no secret. Its tworeach:legs are a named real producer (the published skill) and one public entry measured wrong once (os validate).Filed by the
domain:servicesseat (#6021,session_017B6YKCGu8CTY2KBWgwaHAs) from the #20529 dev report5882379577(out_of_scope_findings, entries 2 and 3) and PR #20551. ⛔ Filed unassigned and unlabelled: routing and grading are triage's. ⛔ Not a claim.Readers who act:
skills/**half is a Tier H governed surface, so it lands through the skills lane and a maintainer's approval.os validatehalf ispackages/lintorpackages/spec, which are spec-lane anchors.Governing text
ADR-0041 (
docs/adr/0041-flow-trigger-family.md, Accepted), thetrigger-apiacceptance criteria: "Per-flow inbound endpoint (POST /api/v1/automation/hooks/:flowName/:hookId) with a per-flow secret; HMAC signature verification (GitHub/Stripe style) and a constant-time compare." PR #20551 (Fixes #20529) makes the runtime enforce this: anapiflow with no non-blankconfig.secretis refused at registration (400 VALIDATION_FAILEDon the/automationwrite doors; skipped with a warning at boot) and at arm time.Locations (read at
origin/main03b19d9c)skills/objectstack-automation/SKILL.md:356, the published skill an authoring agent loads. Thesecretrow reads: "HMAC-SHA256 shared secret. Strongly recommended — without it unsigned posts are accepted and a warning is logged". This contradicts the Accepted ADR today, and after PR fix(trigger-api,service-automation): refuse an api flow with no per-flow secret, at arm time and at registration (#20529) #20551 it describes behaviour the runtime no longer has.git grep -n "Strongly recommended — without it unsigned posts are accepted" origin/main -- skills/objectstack-automation/SKILL.md, expect 1 hit. Positive control:git grep -c "Inbound webhook triggers" origin/main -- skills/objectstack-automation/SKILL.md, expect 1.skills/objectstack-automation/SKILL.md:52. Theapirow reads: "Invoked explicitly via the API /engine.execute(), or bound as an inbound webhook". The engine binds EVERYapi-kind flow to the inbound trigger, so there is no "invoked explicitly only" form oftype: 'api'. After PR fix(trigger-api,service-automation): refuse an api flow with no per-flow secret, at arm time and at registration (#20529) #20551, an author following this row without a secret gets a refused flow. The explicit-only form istype: 'autolaunched'(PR fix(trigger-api,service-automation): refuse an api flow with no per-flow secret, at arm time and at registration (#20529) #20551's changeset says so).git grep -n "Invoked explicitly via the API" origin/main -- skills/objectstack-automation/SKILL.md, expect 1 hit. Positive control: same as item 1.os validatepasses a secretlessapiflow. Measured by the trigger-api arms a flow's inbound hook without a secret and accepts unsigned posts; ADR-0041's trigger-api acceptance criteria name a per-flow secret and HMAC verification #20529 dev on a throwaway stack declaring onetype: 'api'flow with noconfig.secret:✓ Validation passed, exit 0.os validatenever builds the engine or callsregisterFlow. Its authoring-time rule for flow triggers,packages/lint/src/validate-flow-trigger-readiness.ts, has no secret leg.git grep -c secret origin/main -- packages/lint/src/validate-flow-trigger-readiness.ts, expect 0. Positive control:git grep -c triggerType origin/main -- packages/lint/src/validate-flow-trigger-readiness.ts, expect 39.objectstack validatereports nothing for exactly the blankconfig.conditionthatregisterFlownow refuses — and a test pins that silence #17495 (closedcompleted): "objectstack validatereports nothing for exactly the blankconfig.conditionthatregisterFlownow refuses".os validateruns only the stack schema parse, so a config that exports a plain object (nodefineStack()call) skips every defineStack cross-field refusal and passes #20367 / PR feat(spec,cli)!: one stack authoring shape — os validate / os build refuse a default export defineStack did not build #20460 (domain:spec, in flight) makesos validaterun the stack'sdefineStackrefusals. This engine refusal is not one of them, so that PR does not cover it.Not in this card
config.secreton the start node) is served in cleartext by the flow-definition read; after #20529 every armed hook carries one #20552, the security finding from the same report.Dedupe
Semantic
search_issuesonobjectstack-ai/objectstack, open and closed:sys_http_deliveryrow #7722, both outbound webhooks).objectstack validatereports nothing for exactly the blankconfig.conditionthatregisterFlownow refuses — and a test pins that silence #17495 (closedcompleted, blankconfig.condition, the precedent class). None covers theapisecret.Dedupe words:
objectstack-automation skill api secret optional·os validate api flow secret·validate-flow-trigger-readiness secret·type api invoked explicitly