#97 FTX-97: purge foreign/legacy RunFlow credentials from bindings; sync worker must skip disabled bindings

closed high bug Created 2026-07-31 17:25 · Updated 2026-07-31 17:28

Description

Edit
EARS SPEC: - The Futex RunFlow sync worker shall not call RunFlow for a binding whose status is not active. - If a sync job references a non-active binding, then the worker shall dead-letter the job with a reason identifying the disabled binding. - Futex shall provide an operator command that disables every RunFlow binding holding a non-issued (bare tenant-UUID) credential and overwrites the stored credential material. - When a binding credential is purged, Futex shall write an audit event recording the binding, the tenant and the reason. - If a binding still gates an active decision, then the purge command shall refuse to purge it and shall report it for manual handling. CONTEXT: 23 prod bindings hold 7 distinct bare-UUID credentials, 8 of them mail-api's tenant (ead69607-...). All are inert post-cutover, but a foreign platform's credential must not sit at rest in our database. Disclosed to mail-api on thr-e63185dde48244e28ce1 with a commitment to purge.

Comments

Loading comments...

Context

Loading context...

Audit History

View All
Loading audit history...