#97 FTX-97: purge foreign/legacy RunFlow credentials from bindings; sync worker must skip disabled bindings
Description
EditEARS SPEC:
- The Futex RunFlow sync worker shall not call RunFlow for a binding whose status is not active.
- If a sync job references a non-active binding, then the worker shall dead-letter the job with a reason identifying the disabled binding.
- Futex shall provide an operator command that disables every RunFlow binding holding a non-issued (bare tenant-UUID) credential and overwrites the stored credential material.
- When a binding credential is purged, Futex shall write an audit event recording the binding, the tenant and the reason.
- If a binding still gates an active decision, then the purge command shall refuse to purge it and shall report it for manual handling.
CONTEXT: 23 prod bindings hold 7 distinct bare-UUID credentials, 8 of them mail-api's tenant (ead69607-...). All are inert post-cutover, but a foreign platform's credential must not sit at rest in our database. Disclosed to mail-api on thr-e63185dde48244e28ce1 with a commitment to purge.
Comments
Loading comments...
Context
Loading context...
Audit History
View AllLoading audit history...