>_
.issue.db
/issues
Dashboard
Issues
Memory
Lessons
Audit Log
New Issue
Edit Issue #102
Update issue details
Title *
Description
EARS SPEC: - When a RunFlow binding is created, Futex shall verify that the supplied credential can read the bound workflow before storing the binding. - If the credential cannot see the bound workflow, then Futex shall refuse the binding with HTTP 422 identifying a wrong-tenant or unknown-workflow credential. - If RunFlow cannot be reached while validating a binding, then Futex shall answer 503 and shall not store the binding. - Where binding validation is disabled by configuration, the shape check on the credential shall still apply. CAUSE (RunFlow, thr-400b92e261b44c42aa1f): 'nothing validated WHICH tenant a credential belonged to, so demo paste-ins were indistinguishable from deliberate configuration'. FTX-95 found 23 prod bindings holding seven different tenant credentials, 8 of them another platform's. The rak_ shape check added in FTX-95 stops the retired form but not a well-formed credential for the wrong tenant. EVIDENCE the check is possible: our issued key returns 404 on mail-api's workflow 01KYECB52PGKE4AQX4DWCZQZ0X and 200 on our own — tenant isolation is observable at binding time.
Priority
Low
Medium
High
Critical
Status
Open
In Progress
Closed
Won't Do
Due Date (YYYY-MM-DD)
Tags (comma separated)
Related Issues (IDs)
Enter IDs of issues related to this one. They will be linked as 'related'.
Update Issue
Cancel