Found while verifying an authorization-class candidate from the 17.7 pre-release console run #21782 (access-security.share-link-landing-page area, outside the item's clauses), by an independent verifier (RUNNER rule 7) on current main.
- Class: credential handling. Three related shortfalls in how a password-protected share link's password is returned, stored and transmitted. No disclosure to a principal other than the one who set the password was found. Under RUNNER rule 2 the detail is withheld pending maintainer and held in the PM session (Claude Code session
session_018zT8d8NpiQ1ExhuNd5TxY6).
- Direction: the password never travels back out of the server in any form; its stored form uses a slow password hash; the console sends it in a header, not in the request URL.
- Side issue (UX, not security): the landing page shows a password prompt for a link that requires sign-in.
- Severity as judged by the verifier: low. Predates 17.6.0.
- Owning repos:
objectstack (server) and objectui (console transport). No open card covers it.
Generated by Claude Code
Found while verifying an authorization-class candidate from the 17.7 pre-release console run #21782 (
access-security.share-link-landing-pagearea, outside the item's clauses), by an independent verifier (RUNNER rule 7) on currentmain.session_018zT8d8NpiQ1ExhuNd5TxY6).objectstack(server) andobjectui(console transport). No open card covers it.Generated by Claude Code