Skip to content

qa(checklist): add items for the security fixes landed in the 17.7 pre-release follow-up #21932

Description

@objectstack-fleet

Requested by the maintainer in Claude Code session session_018zT8d8NpiQ1ExhuNd5TxY6, 2026-10-06 (「两张卡都开」).

The 17.7 pre-release runs (#21782, #21784, #21845) led to a set of security fixes. The platform checklist (docs/qa/platform-checklist/) has not caught up with the rules they introduced. A keyword pass over the checklist found these gaps. Each row names a rule, not a reproduction.

Fix Checklist today Item to add or extend
#21792 (keyed digest for secret settings, PR merged) no item the settings audit trail stores no digest of a secret-valued setting that a reader can match offline; a read-only holder sees no value
#21846 → #21872 (implicit account linking) one item, older rule an external sign-in does not link implicitly to an unverified local user; after an unlink, implicit sign-in does not re-link; an explicit, signed-in link still works; the platform IdP exception holds only on its OAuth path
#21839 → #21890 (share-link password) items exist, new behaviour missing no exit returns the stored hash; the password is accepted from the X-Share-Password header; public resolve and messages responses carry Cache-Control: no-store
#21835 → #21864 (public-form withdrawal, in flight) withdrawal items exist, layering missing an env-wide withdrawal is not re-opened by an org overlay; only an explicit false withdraws; a package's shipped false withdraws; the env-wide definition may open a package-closed form; the ruled known limit is recorded as a known gap
#21836 → #21879 (global search skips unreadable objects) one item add the two cases #21880 lists: row scope still narrows a searched object; a term present only in a field hidden from the caller yields no hit
#21867 → #21928 (run-state trigger record mask, in flight) added by that PR none, beyond confirming that it lands

Also re-check these two:

Suggested method: the checklist-author skill, scoped to the PRs above, one items PR.

Done when every row above has an item or clause on main with its automated.ref or run steps, check:platform-checklist is green, and the two re-checks are resolved.


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

documentationImprovements or additions to documentationdomain:devxpriority:p1High: required for production / M2

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions