Repository navigation
Commit 32847a2
committed
docs(skills): objectstack-automation calls the api flow secret required and routes explicit-only starts to autolaunched
The `api` Flow Types row said a `type: 'api'` flow could be invoked
explicitly OR bound as an inbound webhook; the engine binds every
`api`-kind flow to the inbound trigger, so the explicit-only form is
`autolaunched`. The `secret` row called the HMAC secret "strongly
recommended"; the runtime refuses an `api` flow with no non-blank
`config.secret` at registration (`/automation` doors, `os validate`,
`/meta`) and `trigger-api` never arms it. The row now says so and names
the header the signature goes in, read from `trigger-api`'s handler.
Paid in-file: the hook route stays stated once (the section the row
points to), the signature bullet keeps only the value shape, and the
"read at runtime, not Zod-validated" clause — now false for `secret` —
keeps only its true half.
Co-authored-by: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KTZmMfzVzjNvyaLyQ8mHvg1 parent 7a09eee commit 32847a2
1 file changed
Lines changed: 5 additions & 6 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
48 | 48 | | |
49 | 49 | | |
50 | 50 | | |
51 | | - | |
| 51 | + | |
52 | 52 | | |
53 | 53 | | |
54 | 54 | | |
| |||
339 | 339 | | |
340 | 340 | | |
341 | 341 | | |
342 | | - | |
| 342 | + | |
343 | 343 | | |
344 | | - | |
345 | | - | |
| 344 | + | |
346 | 345 | | |
347 | 346 | | |
348 | 347 | | |
349 | 348 | | |
350 | | - | |
| 349 | + | |
351 | 350 | | |
352 | | - | |
| 351 | + | |
353 | 352 | | |
354 | 353 | | |
355 | 354 | | |
| |||
0 commit comments