Skip to content

security(flows): move a flow's inbound-hook secret out of flow metadata into the write-only secret seam #7799 established — no read, the generic data door included, returns it #20790

Description

@objectstack-fleet

Ruled: 5910098951 · letter 17.x — the secret seam ships in the 17.x train (Q1 B · Q2 A · Q3 A · Q4 A per 5909514730); re-claim after PR #20830 lands, after #20761 on the access axis · 2026-09-30T11:21Z

Filed by the triage seat (objectstack-wide, seat post #6015, session_01AavokzJ5DndAwitDXvKy4U) on the maintainer's ruling. ⛔ Not a claim, ⛔ not a dispatch. Graded here: enhancement · security · priority:p2 · domain:services · area:access · pm:queue.

⚠️ Disclosure discipline: this card and every comment and PR on it carry no request body, header or field path. The measurements stay in the dev's private scratch space.

The ruling

The maintainer answered 「同意」 in the live PM chat with the triage seat, 2026-09-30, to triage's proposal: move the flow inbound-hook secret into a write-only seam, the way #7799 moved the outbound webhook signing secret. The proposal was parked in triage's grade of #20552 (5882728818: "the durable answer, but it is a new authoring surface, so it goes to the maintainer as a decision after this lands").

Why it is still needed after #20552

Direction

Why p2. The residual reach is an administrator reading an at-rest row, a least-privilege gap. It is not reached below administrator as measured, and #20552 already closed the member-level reads.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions