>_
.issue.db
/issues
Dashboard
Issues
Memory
Lessons
Audit Log
New Issue
Edit Issue #97
Update issue details
Title *
Description
EARS SPEC: - The Futex RunFlow sync worker shall not call RunFlow for a binding whose status is not active. - If a sync job references a non-active binding, then the worker shall dead-letter the job with a reason identifying the disabled binding. - Futex shall provide an operator command that disables every RunFlow binding holding a non-issued (bare tenant-UUID) credential and overwrites the stored credential material. - When a binding credential is purged, Futex shall write an audit event recording the binding, the tenant and the reason. - If a binding still gates an active decision, then the purge command shall refuse to purge it and shall report it for manual handling. CONTEXT: 23 prod bindings hold 7 distinct bare-UUID credentials, 8 of them mail-api's tenant (ead69607-...). All are inert post-cutover, but a foreign platform's credential must not sit at rest in our database. Disclosed to mail-api on thr-e63185dde48244e28ce1 with a commitment to purge.
Priority
Low
Medium
High
Critical
Status
Open
In Progress
Closed
Won't Do
Due Date (YYYY-MM-DD)
Tags (comma separated)
Related Issues (IDs)
Enter IDs of issues related to this one. They will be linked as 'related'.
Update Issue
Cancel