Skip to content

Commit ff4d8e7

Browse files
hotlongclaude
andcommitted
Merge remote-tracking branch 'origin/main' into claude/issue-20166-manifest-beside-config
Claude-Session: https://claude.ai/code/session_local_1d2a197c-c20e-4e90-9be8-413d4d432289 Co-authored-by: Claude <noreply@anthropic.com>
2 parents 7c21afd + 6c11ef9 commit ff4d8e7

2 files changed

Lines changed: 9 additions & 3 deletions

File tree

‎content/docs/automation/connectors.mdx‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -114,6 +114,8 @@ Materializes a single **`request`** action accepting
114114
payload per call. Use it when the upstream is "just HTTP" and you don't have a
115115
spec document.
116116

117+
Do not put a credential in `headers` or `defaultHeaders`: both are stored in metadata and served with it. Declare it as `auth.credentialRef` instead — the resolved `auth` is applied to every request — as the `Authorization` header, or for `api-key` as `headerName` (default `X-API-Key`) or the `paramName` query parameter.
118+
117119
### `provider: 'openapi'` — one action per operation
118120

119121
Config: **`spec`** (required) and **`baseUrl`** (optional — overrides the

‎content/docs/automation/flows.mdx‎

Lines changed: 7 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -261,15 +261,19 @@ nothing is assigned or written in its place.
261261
{
262262
id: 'notify_slack',
263263
type: 'http',
264-
label: 'Send Slack Notification',
264+
label: 'Post Order Event',
265265
config: {
266-
url: 'https://hooks.slack.com/services/...',
266+
url: 'https://api.example.com/v1/order-events',
267267
method: 'POST',
268-
body: { text: 'New order: {record.name}' },
268+
body: { event: 'order.created', name: '{record.name}' },
269269
},
270270
}
271271
```
272272

273+
<Callout type="warn" title="Do not put a secret in an http node's url or headers">
274+
A flow definition, including an `http` node's `url` and `headers`, is served to every member who can read flows. A token, API key or signed webhook url written there is readable by all of them. Route an outbound credential to a declarative connector's `auth.credentialRef` and call it with a `connector_action` node instead — see [Connectors](/docs/automation/connectors#authentication). Only `signingSecret` (and a start node's `secret`) is withheld when a definition is served; `url` and `headers` are served as written.
275+
</Callout>
276+
273277
**Script:**
274278

275279
The built-in `script` executor never evaluates an arbitrary JavaScript string —

0 commit comments

Comments
 (0)