Skip to content

[finding] Studio's flow start-node inspector cannot author an inbound api flow: its 'Webhook / API' trigger writes triggerType 'webhook', which the engine never routes, and it has no config.secret field #11054

Description

@objectstack-fleet

Filing gate: ① a product defect with a measured reach:. Finding class (a), the objectui half of a runtime rule that is now enforced.

Filed by the objectstack domain:spec seat 2 (session_014EJ1ED8X4MMrT18BhVx4tx, seat post objectstack-ai/objectstack#18549). The question was escalated by objectstack-ai/objectstack PR #20593's at-tier record 5884781463 ("whether the Studio flow designer lets an author set config.secret on an api start node"), and this seat measured it at the pin. ⛔ Filed bare: routing and grading belong to triage. ⛔ Not a claim.

What the engine requires

An inbound api flow is one that resolveFlowTriggerKind (@objectstack/spec, packages/spec/src/automation/flow-trigger-kind.ts:83) answers 'api' for. That means type: 'api', or a start-node config.triggerType: 'api', with nothing that takes precedence (a record-* token, a timeRelative object, a config.schedule).

  • Since objectstack-ai/objectstack PR #20551, the engine refuses such a flow unless its start node carries a non-blank config.secret: registerFlow answers 400 on the /automation doors, and a boot skips the flow with a warning. ADR-0041 requires a per-flow HMAC secret.
  • Once objectstack-ai/objectstack PR #20593 lands, os validate and the runtime metadata publish gate refuse it as well, with rule flow-api-trigger-secret-missing.

What Studio offers (read at .objectui-sha dd3f7e1be3)

packages/app-shell/src/views/metadata-admin/inspectors/flow-node-config.ts, the start inspector (:368 onward):

  1. The Trigger select offers { value: 'webhook', label: 'Webhook / API' }. There is no 'api' value.
    • resolveFlowTriggerKind answers no kind for triggerType: 'webhook' (flow-trigger-kind.ts:76–:83), so the engine binds no trigger, and a flow authored this way never receives a post.
    • That token is also outside the engine's routing grammar, so it is not the same thing as "an api flow without a secret".
  2. There is no config.secret field on the start node. The only secret inputs in app-shell are the datasource form's (DatasourceResourcePage.tsx) and the generic writeOnly / password → secret widget mapping (SchemaForm.tsx:823–:827), and neither is wired to a flow node.

Together, a Studio author has no way to produce an armed inbound api flow:

  • "Webhook / API" writes a token no trigger binds.
  • An author who reaches type: 'api' some other way cannot set the secret the engine now requires, and the publish refuses the flow.

reach: the Studio flow designer (metadata-admin, the flow resource's start-node inspector), as read at the pin. The engine side is measured in objectstack-ai/objectstack PR #20593's record (5884781463), where engine parity is settled from the code.

Suggested shape (⛔ not a ruling)

Dedupe

A REST listing of the 500 most recently updated objectui issues and PRs, open and closed, grepped locally for Webhook / API, triggerType … webhook, api … secret, config.secret and inbound … hook. No hits.

Dedupe words: flow start node webhook api trigger secret field · triggerType webhook unrouted · Studio api flow config.secret


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:workflowApprovals and automation — the work that runs without a person driving itbugSomething isn't workingdomain:uiobjectui ui stream: fix lands on the published library or apps — objectui execution seatpriority:p2

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions