Skip to content

Commit 32847a2

Browse files
committed
docs(skills): objectstack-automation calls the api flow secret required and routes explicit-only starts to autolaunched
The `api` Flow Types row said a `type: 'api'` flow could be invoked explicitly OR bound as an inbound webhook; the engine binds every `api`-kind flow to the inbound trigger, so the explicit-only form is `autolaunched`. The `secret` row called the HMAC secret "strongly recommended"; the runtime refuses an `api` flow with no non-blank `config.secret` at registration (`/automation` doors, `os validate`, `/meta`) and `trigger-api` never arms it. The row now says so and names the header the signature goes in, read from `trigger-api`'s handler. Paid in-file: the hook route stays stated once (the section the row points to), the signature bullet keeps only the value shape, and the "read at runtime, not Zod-validated" clause — now false for `secret` — keeps only its true half. Co-authored-by: Claude <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KTZmMfzVzjNvyaLyQ8mHvg
1 parent 7a09eee commit 32847a2

1 file changed

Lines changed: 5 additions & 6 deletions

File tree

‎skills/objectstack-automation/SKILL.md‎

Lines changed: 5 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -48,7 +48,7 @@ A **Flow** is a directed graph of nodes — the primary automation building bloc
4848
| `screen` | Interactive — presents UI screens to the user (wizards, forms) |
4949
| `schedule` | Runs on a cron/interval cadence declared on the **start node's `config.schedule`** (daily cleanup, weekly reports) — or a **per-record date sweep** via `config.timeRelative`, see *Time-relative triggers* |
5050
| `record_change` | Fires automatically on record create/update/delete (bind via the `start` node's `triggerType`). `autolaunched` + the same `record-*` binding behaves identically — the engine reads the start node either way; `record_change` also opts into the trigger-readiness lint |
51-
| `api` | Invoked explicitly via the API / `engine.execute()`, **or** bound as an inbound **webhook**: `POST /api/v1/automation/hooks/:flowName/:hookId` (see *Inbound webhook triggers* below) |
51+
| `api` | Inbound **webhook** — every `api` flow is bound to its hook endpoint and needs a start-node `secret` (see *Inbound webhook triggers* below); a flow only ever started explicitly is `autolaunched` |
5252

5353
### Flow Node Types
5454

@@ -339,17 +339,16 @@ defineStack({
339339

340340
### Inbound webhook (`api`) triggers (ADR-0041 Tier 1)
341341

342-
An `api` flow can be bound to an inbound HTTP endpoint:
342+
An `api` flow is bound to an inbound HTTP endpoint:
343343
`POST /api/v1/automation/hooks/:flowName/:hookId`. Configure it on the **start
344-
node `config`** (the start `config` is a free-form record, so these keys are
345-
read at runtime, not Zod-validated):
344+
node `config`** (the start `config` is a free-form record with no Zod shape):
346345

347346
| `config` key | Purpose |
348347
|:-------------|:--------|
349348
| `hookId` | URL path token (default `'default'`). **Rotate it to revoke** a leaked endpoint |
350-
| `secret` | HMAC-SHA256 shared secret. Strongly recommended — without it unsigned posts are accepted and a warning is logged |
349+
| `secret` | HMAC-SHA256 shared secret. **Required** — without a non-blank one the flow is refused at registration (`os validate` too) and never armed at boot; the signature goes in `x-objectstack-signature` |
351350

352-
- **Signature:** sender sends `x-objectstack-signature: sha256=<hex>` (GitHub/Stripe style).
351+
- **Signature:** `sha256=<hex>` (GitHub/Stripe style).
353352
- **Idempotency:** `x-idempotency-key` dedupes retries — author the flow to be idempotent (delivery is at-least-once).
354353
- **Queue-backed:** the endpoint ACKs `202` and enqueues; the flow runs on the consumer, never in-band. Requires the `queue` service (see prerequisite).
355354
- The JSON body surfaces to the flow as the trigger record (`record.*` / bare fields) plus `params`.

0 commit comments

Comments
 (0)