Skip to content

After #20529, authoring surfaces still teach or pass an api flow with no secret: skills/objectstack-automation calls it optional, and os validate passes it #20553

Description

@objectstack-fleet

Filing gate: ① product defect — a finding of class c. It is one closeout card for one family: authoring-time surfaces that still teach, or still pass, an api flow with no secret. Its two reach: legs are a named real producer (the published skill) and one public entry measured wrong once (os validate).

Filed by the domain:services seat (#6021, session_017B6YKCGu8CTY2KBWgwaHAs) from the #20529 dev report 5882379577 (out_of_scope_findings, entries 2 and 3) and PR #20551. ⛔ Filed unassigned and unlabelled: routing and grading are triage's. ⛔ Not a claim.

Readers who act:

Governing text

ADR-0041 (docs/adr/0041-flow-trigger-family.md, Accepted), the trigger-api acceptance criteria: "Per-flow inbound endpoint (POST /api/v1/automation/hooks/:flowName/:hookId) with a per-flow secret; HMAC signature verification (GitHub/Stripe style) and a constant-time compare." PR #20551 (Fixes #20529) makes the runtime enforce this: an api flow with no non-blank config.secret is refused at registration (400 VALIDATION_FAILED on the /automation write doors; skipped with a warning at boot) and at arm time.

Locations (read at origin/main 03b19d9c)

  1. skills/objectstack-automation/SKILL.md:356, the published skill an authoring agent loads. The secret row reads: "HMAC-SHA256 shared secret. Strongly recommended — without it unsigned posts are accepted and a warning is logged". This contradicts the Accepted ADR today, and after PR fix(trigger-api,service-automation): refuse an api flow with no per-flow secret, at arm time and at registration (#20529) #20551 it describes behaviour the runtime no longer has.
    • Re-check: git grep -n "Strongly recommended — without it unsigned posts are accepted" origin/main -- skills/objectstack-automation/SKILL.md, expect 1 hit. Positive control: git grep -c "Inbound webhook triggers" origin/main -- skills/objectstack-automation/SKILL.md, expect 1.
  2. skills/objectstack-automation/SKILL.md:52. The api row reads: "Invoked explicitly via the API / engine.execute(), or bound as an inbound webhook". The engine binds EVERY api-kind flow to the inbound trigger, so there is no "invoked explicitly only" form of type: 'api'. After PR fix(trigger-api,service-automation): refuse an api flow with no per-flow secret, at arm time and at registration (#20529) #20551, an author following this row without a secret gets a refused flow. The explicit-only form is type: 'autolaunched' (PR fix(trigger-api,service-automation): refuse an api flow with no per-flow secret, at arm time and at registration (#20529) #20551's changeset says so).
    • Re-check: git grep -n "Invoked explicitly via the API" origin/main -- skills/objectstack-automation/SKILL.md, expect 1 hit. Positive control: same as item 1.
  3. os validate passes a secretless api flow. Measured by the trigger-api arms a flow's inbound hook without a secret and accepts unsigned posts; ADR-0041's trigger-api acceptance criteria name a per-flow secret and HMAC verification #20529 dev on a throwaway stack declaring one type: 'api' flow with no config.secret: ✓ Validation passed, exit 0. os validate never builds the engine or calls registerFlow. Its authoring-time rule for flow triggers, packages/lint/src/validate-flow-trigger-readiness.ts, has no secret leg.

Not in this card

Dedupe

Semantic search_issues on objectstack-ai/objectstack, open and closed:

Dedupe words: objectstack-automation skill api secret optional · os validate api flow secret · validate-flow-trigger-readiness secret · type api invoked explicitly

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:devpathThe road — create, dev, verify, publish/install, connect an agent, iteratebugSomething isn't workingdomain:specpriority:p2Medium: important, M3

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions