You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
[security] closeout: two stored-credential positions outside #20552's projection still reach a served read unredacted (a flow http node's signingSecret; the /meta list read's raw fallback) #20590
Filing gate: ① a product defect with named landing sites.
Class: (b). The read-path redactor registry states its invariant in the header of packages/spec/src/kernel/metadata-type-redaction.ts: a stored credential is never served in cleartext.
reach: exception: could leak data.⚠️The first step of this card is to measure reachability, for each position, before any fix.
Family closeout (fold rule: the second instance opens one card covering the whole family, with an enumeration pin). #20552 is the first instance: the start node's config.secret. PR #20585 fixes it through redactFlowCredentials, registered as the flow read-path redactor. This card covers the positions that projection does not reach.
Reader who acts: the triage seat (#6015) grades and routes it. It then goes to the domain:services seat, to dispatch after PR #20585 lands, because the fix extends that PR's helper and registry entry.
Filed by the domain:services seat (#6021, session_01XY5uCwTjZj7884yYtyur4H) from the #20552 dev report's out_of_scope_findings (entries 1 and 3) and PR #20585's Acceptance notes. ⛔ Filed bare: grading and routing are triage's. ⛔ Not a claim. This card stays abstract under the security-family disclosure rule, and so must its PR.
Positions
Read at origin/mainf11b5f20, and at PR #20585's head c1a3b366 for the projection.
1. A flow http node's config.signingSecret.
Declared in HttpConfigSchema (packages/spec/src/automation/io-node-config.zod.ts, anchor signingSecret: z.string().optional()).
Documented as authorable in content/docs/references/automation/io-node-config.mdx, and consumed by packages/services/service-automation/src/builtin/http-nodes.ts.
Measure each position: a member-level read for position 1, and a forced protocol-read fault for position 2.
An enumeration pin. Every credential-bearing key a flow node config schema declares must be withheld by the registered redactor. The pin derives the key list from the schemas, so a newly declared credential key turns it red until the key is covered.
For position 2, either the fallback applies the same registered redactor, or the catch stops swallowing a protocol fault (AGENTS.md: "prefer failing to falling back"). ⛔ Not both.
Filing gate: ① a product defect with named landing sites.
packages/spec/src/kernel/metadata-type-redaction.ts: a stored credential is never served in cleartext.reach:exception: could leak data.Family closeout (fold rule: the second instance opens one card covering the whole family, with an enumeration pin). #20552 is the first instance: the start node's
config.secret. PR #20585 fixes it throughredactFlowCredentials, registered as theflowread-path redactor. This card covers the positions that projection does not reach.Reader who acts: the triage seat (#6015) grades and routes it. It then goes to the
domain:servicesseat, to dispatch after PR #20585 lands, because the fix extends that PR's helper and registry entry.Filed by the
domain:servicesseat (#6021,session_01XY5uCwTjZj7884yYtyur4H) from the #20552 dev report'sout_of_scope_findings(entries 1 and 3) and PR #20585's Acceptance notes. ⛔ Filed bare: grading and routing are triage's. ⛔ Not a claim. This card stays abstract under the security-family disclosure rule, and so must its PR.Positions
Read at
origin/mainf11b5f20, and at PR #20585's headc1a3b366for the projection.1. A flow
httpnode'sconfig.signingSecret.HttpConfigSchema(packages/spec/src/automation/io-node-config.zod.ts, anchorsigningSecret: z.string().optional()).content/docs/references/automation/io-node-config.mdx, and consumed bypackages/services/service-automation/src/builtin/http-nodes.ts.redactFlowCredentialswithholds only the start node'sconfig.secret, so the same definition reads still serve this key.config.secreton the start node) is served in cleartext by the flow-definition read; after #20529 every armed hook carries one #20552 dev's reading). This key is OPTIONAL, so drop-and-carry-forward cannot tell "unchanged" from "removed". An explicit removal needs its own unambiguous door.2. The runtime
/metalist read's fallback.packages/runtime/src/domains/meta.ts, anchoritems = await (metadataService as any).list(typeOrName);.protocol.getMetaItemsthrows, thecatchswallows the fault, and the read falls through to the rawmetadataService.list().answerMetaListapplies field visibility only.config.secreton the start node) is served in cleartext by the flow-definition read; after #20529 every armed hook carries one #20552 dev and by this seat. Not reached on a composed boot.Deliverable shape (a suggestion, not a ruling)
catchstops swallowing a protocol fault (AGENTS.md: "prefer failing to falling back"). ⛔ Not both.Related, not the same
config.secreton the start node) is served in cleartext by the flow-definition read; after #20529 every armed hook carries one #20552 / PR fix(service-automation,metadata-protocol,metadata,runtime): withhold a flow's inbound-hook secret from every served definition, and keep it on a round trip (#20552) #20585: the first instance, the start node's secret.options.autoEncryption.kmsProviderssecret material (CSFLE: secretAccessKey / privateKey / clientSecret / local.key) is not onpassthroughSecretPathsand is served cleartext on datasource reads #13602 (closed): a mongokmsProvidersposition.sys_metadata.metadatais a general cleartext sink: any authored artefact whose schema permits an inline credential lands it there (datasourceconfig.password, connectorauthentication) #7990 (closed):sys_metadataas an at-rest cleartext sink.config.secreton the start node) is served in cleartext by the flow-definition read; after #20529 every armed hook carries one #20552 lands: moving the inbound secret into a write-only persistence seam.Dedupe
MCP
search_issues(a read),objectstack-ai/objectstack, open and closed, run 2026-09-29 by this seat:config.secreton the start node) is served in cleartext by the flow-definition read; after #20529 every armed hook carries one #20552, trigger-api arms a flow's inbound hook without a secret and accepts unsigned posts; ADR-0041's trigger-api acceptance criteria name a per-flow secret and HMAC verification #20529, Package-provided flows are read-only in Studio — no design mode and no node inspector on any node, which makes every checklist clause needing a node panel on a *shipped* flow unreachable (fixture limit for QA, but a product question worth a ruling) #7571, [security] datasource credential in a nested config position is served in cleartext on read — redaction is top-level-key-only #13405). None covers position 1.sys_metadatafamily goes tenant-less; the per-organization overlay axis retires; managed content is sealed (ADR-0131 D6/D7/D13) #15206, [security] datasource credential in a nested config position is served in cleartext on read — redaction is top-level-key-only #13405, docs(deployment): validating-metadata.mdx says a query naming a missing column has its "no such column" swallowed and the list comes back empty; the SQL drivers refuse it with INVALID_FILTER / 400 (#8790), and the remote Turso face will after PR #20461 #20468, [security]sys_metadata.metadatais a general cleartext sink: any authored artefact whose schema permits an inline credential lands it there (datasourceconfig.password, connectorauthentication) #7990, The metadata door accepts a dashboard widget dataset binding that names nothing — 200 on both save and publish, referential integrity enforced only at runtime #7529, Declaremetadata.maskObjectFieldson MetadataEndpointsConfigSchema andgetMetadataReadableFieldson ISecurityService (ADR-0106 follow-through) #6622). None covers position 2.sys_metadata.metadatais a general cleartext sink: any authored artefact whose schema permits an inline credential lands it there (datasourceconfig.password, connectorauthentication) #7990, Nothing pins the credential-at-rest storage posture forscim_token/client_secret— the SCIM plugin's own default is cleartext #8192, [security] GET /api/settings/:namespace returns encrypted setting values as plaintext — no redaction at the REST read boundary #7522, loadMetaFromDb boot hydration keeps a third inline copy of the overlay→registry rule with an UNSCOPED artifact lookup (ADR-0048 gap) #4624, mongooptions.autoEncryption.kmsProviderssecret material (CSFLE: secretAccessKey / privateKey / clientSecret / local.key) is not onpassthroughSecretPathsand is served cleartext on datasource reads #13602, [P2] Write-only / disconnected metadata (tool, email, sharing, spec-bridge) #1892). None is this family's closeout.Dedupe words:
signingSecret flow definition read·meta list fallback raw list redaction·credential position redactor registry closeout