Requested by the maintainer in Claude Code session session_018zT8d8NpiQ1ExhuNd5TxY6, 2026-10-06 (「两张卡都开」).
The 17.7 pre-release runs (#21782, #21784, #21845) led to a set of security fixes. The platform checklist (docs/qa/platform-checklist/) has not caught up with the rules they introduced. A keyword pass over the checklist found these gaps. Each row names a rule, not a reproduction.
| Fix |
Checklist today |
Item to add or extend |
| #21792 (keyed digest for secret settings, PR merged) |
no item |
the settings audit trail stores no digest of a secret-valued setting that a reader can match offline; a read-only holder sees no value |
| #21846 → #21872 (implicit account linking) |
one item, older rule |
an external sign-in does not link implicitly to an unverified local user; after an unlink, implicit sign-in does not re-link; an explicit, signed-in link still works; the platform IdP exception holds only on its OAuth path |
| #21839 → #21890 (share-link password) |
items exist, new behaviour missing |
no exit returns the stored hash; the password is accepted from the X-Share-Password header; public resolve and messages responses carry Cache-Control: no-store |
| #21835 → #21864 (public-form withdrawal, in flight) |
withdrawal items exist, layering missing |
an env-wide withdrawal is not re-opened by an org overlay; only an explicit false withdraws; a package's shipped false withdraws; the env-wide definition may open a package-closed form; the ruled known limit is recorded as a known gap |
| #21836 → #21879 (global search skips unreadable objects) |
one item |
add the two cases #21880 lists: row scope still narrows a searched object; a term present only in a field hidden from the caller yields no hit |
| #21867 → #21928 (run-state trigger record mask, in flight) |
added by that PR |
none, beyond confirming that it lands |
Also re-check these two:
Suggested method: the checklist-author skill, scoped to the PRs above, one items PR.
Done when every row above has an item or clause on main with its automated.ref or run steps, check:platform-checklist is green, and the two re-checks are resolved.
Generated by Claude Code
Requested by the maintainer in Claude Code session
session_018zT8d8NpiQ1ExhuNd5TxY6, 2026-10-06 (「两张卡都开」).The 17.7 pre-release runs (#21782, #21784, #21845) led to a set of security fixes. The platform checklist (
docs/qa/platform-checklist/) has not caught up with the rules they introduced. A keyword pass over the checklist found these gaps. Each row names a rule, not a reproduction.X-Share-Passwordheader; public resolve and messages responses carryCache-Control: no-storeAlso re-check these two:
integration-system.datasource-credential-refusal-matrix:config: that is the plugin author's responsibility, per the docs note in docs(drivers): a plugin driver's config is its author's to keep free of credentials #21927.npm installfails on a pnpm-installed scaffold) and the quorum N1 note were also applied.Suggested method: the
checklist-authorskill, scoped to the PRs above, one items PR.Done when every row above has an item or clause on
mainwith itsautomated.refor run steps,check:platform-checklistis green, and the two re-checks are resolved.Generated by Claude Code