You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
security(datasource): credential-shaped values in some datasource configurations are stored and served without the platform's secret handling — detail withheld pending maintainer #21840
Found while verifying a candidate from the 17.7 pre-release console run #21784 (integration-system area, outside the item's clauses), by an independent verifier (RUNNER rule 7) on current main.
Class: secret hygiene. For some datasource configurations, credential-shaped values are kept at rest and served on admin reads without going through the secret store or redaction the platform applies elsewhere. Reachable only by platform administrators; no lower-privilege read was found. Under RUNNER rule 2 the detail is withheld pending maintainer, held in the PM session (Claude Code session session_018zT8d8NpiQ1ExhuNd5TxY6).
Direction: credential-shaped datasource values go to the secret store (or are refused at write, as other configurations already are), and every read door redacts them.
Found while verifying a candidate from the 17.7 pre-release console run #21784 (
integration-systemarea, outside the item's clauses), by an independent verifier (RUNNER rule 7) on currentmain.session_018zT8d8NpiQ1ExhuNd5TxY6).options.autoEncryption.kmsProviderssecret material (CSFLE: secretAccessKey / privateKey / clientSecret / local.key) is not onpassthroughSecretPathsand is served cleartext on datasource reads #13602.objectstack. No open card covers it.Generated by Claude Code