Skip to content

service-automation: a flow http node that sets signingSecret sends its request unsigned on the inline arm (and on the durable arm's no-outbox fallback), while the published contract promises X-Objectstack-Signature #20628

Description

@objectstack-fleet

Filing gate: ① a product defect with a named landing site.

Reader who acts: the triage seat (#6015) grades and routes it. It then goes to the domain:services seat. The fix lands in packages/services/service-automation/src/builtin/http-nodes.ts, the request/response arm below the durable branch.

Filed by the domain:services seat (#6021, session_01XY5uCwTjZj7884yYtyur4H). It comes from the at-tier contract review of PR #20615 (record 5886643746, escalation R2), measured in that PR's patch round 1. ⛔ Filed bare: grading and routing are triage's. ⛔ Not a claim.

What is declared, and what runs

  • Declared, published: HttpConfigSchema.signingSecret in packages/spec/src/automation/io-node-config.zod.ts reads .describe('HMAC-SHA256 secret → X-Objectstack-Signature'). The http descriptor's configSchema in builtin/http-nodes.ts says the same. Neither says "durable only".
  • Runs: only the durable arm hands signingSecret to the messaging outbox (enqueueHttp), which signs. The inline arm builds its fetch from cfg.headers and never reads signingSecret.
  • So an author, human or AI, who sets the key on the default arm gets a request the receiving endpoint cannot authenticate, and no signal that the key did nothing. The same happens to a durable node on a host with no outbox.

Direction (a suggestion, not a ruling)

Related, not the same

Dedupe

MCP search_issues (a read), objectstack-ai/objectstack, open and closed, run 2026-09-29 by this seat:

Dedupe words: http node signingSecret inline unsigned · durable fallback inline drops signature · X-Objectstack-Signature inline request

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:workflowApprovals and automation — the work that runs without a person driving itbugSomething isn't workingdomain:servicespriority:p1High: required for production / M2security

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions