#102 FTX-102: a RunFlow binding accepts a credential that cannot see its own workflow
Description
EditEARS SPEC:
- When a RunFlow binding is created, Futex shall verify that the supplied credential can read the bound workflow before storing the binding.
- If the credential cannot see the bound workflow, then Futex shall refuse the binding with HTTP 422 identifying a wrong-tenant or unknown-workflow credential.
- If RunFlow cannot be reached while validating a binding, then Futex shall answer 503 and shall not store the binding.
- Where binding validation is disabled by configuration, the shape check on the credential shall still apply.
CAUSE (RunFlow, thr-400b92e261b44c42aa1f): 'nothing validated WHICH tenant a credential belonged to, so demo paste-ins were indistinguishable from deliberate configuration'. FTX-95 found 23 prod bindings holding seven different tenant credentials, 8 of them another platform's. The rak_ shape check added in FTX-95 stops the retired form but not a well-formed credential for the wrong tenant.
EVIDENCE the check is possible: our issued key returns 404 on mail-api's workflow 01KYECB52PGKE4AQX4DWCZQZ0X and 200 on our own — tenant isolation is observable at binding time.
Comments
Loading comments...
Context
Loading context...
Audit History
View AllLoading audit history...