docs(qa): checklist items for the 17.7 pre-release security fixes - #21943
Merged
objectstack-fleet[bot] merged 1 commit intoOct 6, 2026
Merged
Conversation
Adds three items and extends two for the rules the 17.7 pre-release follow-up landed: - platform-core.settings-audit-secret-fingerprint (new): the settings audit trail fingerprints a secret-valued setting with the keyed digest or not at all, never the value or an unkeyed hash. - identity-auth.implicit-account-linking-ownership (new): no implicit link to an unverified local user, an unlink is honoured, the explicit signed-in link still works, the platform IdP exception holds only on its OAuth path. - search.global-search-skips-unreadable (new): global search skips unreadable objects and fields instead of failing; row scope still narrows; a term only in a hidden field yields no hit. - access-security.share-link-capability-tokens rev 5: the stored hash never leaves, the X-Share-Password header, no-store on public answers. - integration-system.datasource-credential-refusal-matrix rev 3: A2/A7 recorded as a known environment gap; the unknown-driver clause states the ruled plugin-driver boundary. Claude-Session: https://claude.ai/code/session_01VDtqoecgES7ScQYGbFVDRv Co-authored-by: Claude <noreply@anthropic.com>
objectstack-fleet
Bot
deleted the
claude/issue-21932-checklist-17-7-security
branch
October 6, 2026 03:43
This was referenced Oct 6, 2026
Closed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part of #21932
Clause-②: no
What changes
The platform checklist gains items for the rules the 17.7 pre-release security follow-up landed, and two re-checks from the card are resolved. All edits are in
docs/qa/platform-checklist/areas/*.json.automation.jsonis untouched (open PR #21928 holds it).platform-core.settings-audit-secret-fingerprintidentity-auth.implicit-account-linking-ownershipaccess-security.share-link-capability-tokenssearch.global-search-skips-unreadableintegration-system.datasource-credential-refusal-matrixcli.scaffold-first-run,cli.scaffold-console-first-paint,approvals.quorum-m-of-nEach item states rules, not reproductions. Withheld security detail stays out.
Grounding, per row
settings-service.ts#secretAuditDigest,config-change-audit.ts#CONFIG_CHANGE_ACTIONand the contract text atcrypto-provider.ts#keyedDigest. The pin issettings-audit-secret-digest.test.ts(7 cases). The offline check carries a positive control: the non-secret key's unkeyed digest IS found, so a no-hit on the secret rows means something. The no-keyed-digest arm cannot be reached on a stock boot, so that clause is scored from the pin.implicit-account-linking.ts(decideImplicitLink,IMPLICIT_LINK_REFUSED,PLATFORM_IDP_PROVIDER_ID,recordUnlinkTombstone,refuseImplicitAccountLink) and the publishedsso.mdxsection. The pin isimplicit-account-linking.test.ts. The item reuses the local OIDC provider recipe fromidentity-auth.linked-accounts-social. The platform-IdP clause and the operator override are pin-scored, and knownGaps says why.X-Share-Passwordheader, the query form is still accepted, and the default CORS allow-list carries the header. Both public routes answerCache-Control: no-storeandVary: X-Share-Passwordon every outcome, and the authenticated routes do not. Grounded inshare-link-service.ts#withoutPasswordHash,share-link-routes.ts#SHARE_LINK_PUBLIC_RESPONSE_HEADERS, the runtimeshare-links.ts#PUBLIC_RESPONSE_HEADERSandadapter.ts#DEFAULT_CORS_ALLOW_HEADERS. The pins are the[#21839]blocks inshare-link-password.test.ts,share-links-public-cache-headers.test.tsand the hono-plugin CORS case. Existing clause indices are unchanged.objects=naming one answers exactly as a name that matches no object. The object stays refused at its own door. Row scope still narrows a searched object, and a term found only in a field hidden from the caller yields no hit. Grounded inprotocol.ts#searchAll(thecanReadObjectpre-filter and thegetQueryableFieldsnarrowing). The pins are the dogfoodsearch-skip-unreadable.dogfood.test.tsand the 12 unit cases inprotocol.search-skip-unreadable.test.ts. The two security(search): a field-narrowed search still matches through the name field's pinyin companion #21880 cases have no end-to-end pin yet, and knownGaps says so. The open pinyin-companion finding on security(search): a field-narrowed search still matches through the name field's pinyin companion #21880 is recorded as a knownGap with a flag-off instruction, at class level only. The persona reuses the area recipeqa-contributor-bound-member.acceptance[1]andacceptance[6]) are recorded as a known environment gap. They need a reachable credential-protected database of a shipped driver, which no run has had. No recipe is claimed, because none is proven. A successful publish alone may not score them, and the stored-credential half of A7 can be read as a partial reading. Separately, the unknown-driver clause, step 7, its negative and the title now state the ruled boundary from decision: how a datasource driver with no shipped config contract keeps credentials out of metadata (declaration vs. key-name heuristic) #21921 and the docs note docs(drivers): a plugin driver's config is its author's to keep free of credentials #21927. For a plugin driver, only the fixed spellings are redacted (the canonical keys, the former aliases and URL credentials). A non-canonical key served as written is the boundary, not a FAIL. Grounded incommon.zod.ts#CANONICAL_CREDENTIAL_KEYSanddatasource-credential-redaction.ts#redactableConfigKeys.Re-check 2 evidence (no edit)
At the claim ref
9dce635337:cli.scaffold-first-run(rev 3) step 0 andcli.scaffold-console-first-paint(rev 3) step 0 both drop the trailingnpm installand warn against adding it. Their rev 3 history entries cite QA run · follow-up: 6 previously unrun or published-only items (6/6) · 316be321 + 53021e3a · 2026-10-05 · 4 PASS / 0 PARTIAL / 2 FAIL / 0 BLOCKED / 0 NOT-RUN #21845. No othernpm installstep remains incli.json.approvals.quorum-m-of-n(rev 4)negative[0]requires a NON-PRIVILEGED repeat actor and names the documented admin override (Approval routed to an empty position permanently locks the record (no admin override, no recovery) #3424) as never a distinctness FAIL.Remaining on #21932 (held, not in this PR)
automation.json.#21932 remains open for these two rows.
Validation (at
a72b827e43)pnpm check:platform-checklist: exit 0. It reports 15 areas and 273 items (269 active, 2 planned). The baseline was 270. Symbol anchors resolve 674 of 684 (baseline 657 of 667): all 17 new anchors resolve, and the [finding] the platform-checklist corpus resolves symbol anchors with its OWN rule, not the shared resolver — a permissive token match where the ruling says there is to be exactly one implementation #16898 residual is unchanged at 10.node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstackderived 13 commands, and all 13 exit 0.check:doc-formula-expressionsfirst exited 3 (PREREQUISITE NOT MET:@objectstack/formulaand@objectstack/lintwere not built). After building them it exited 0.--ranreconciliation: 13 derived, 13 run, 0 unrun.docs/qa/**publishes nothing.Acceptance notes
check:platform-checklistrefuses afile:linepin.content/docs/data-modeling/drivers.mdxsays a plugin driver'sconfigis "stored and served to administrators as written". The read redactor still withholds the canonical spellings (password,authToken), the former aliases and URL credentials for such a driver (redactableConfigKeys). So the docs sentence is slightly broader than the code, and the code is the more protective of the two. The checklist follows the code. This is noted only, with no card. Carrier: none.search.global-search-skips-unreadablepicks the walled object and the hidden-field value on the live boot, behind premise guards. The item names likely candidates and does not assume them.Generated by Claude Code