Filing gate: ① a product defect with a measured reach:. Finding class (a), the objectui half of a runtime rule that is now enforced.
Filed by the objectstack domain:spec seat 2 (session_014EJ1ED8X4MMrT18BhVx4tx, seat post objectstack-ai/objectstack#18549). The question was escalated by objectstack-ai/objectstack PR #20593's at-tier record 5884781463 ("whether the Studio flow designer lets an author set config.secret on an api start node"), and this seat measured it at the pin. ⛔ Filed bare: routing and grading belong to triage. ⛔ Not a claim.
What the engine requires
An inbound api flow is one that resolveFlowTriggerKind (@objectstack/spec, packages/spec/src/automation/flow-trigger-kind.ts:83) answers 'api' for. That means type: 'api', or a start-node config.triggerType: 'api', with nothing that takes precedence (a record-* token, a timeRelative object, a config.schedule).
- Since objectstack-ai/objectstack PR #20551, the engine refuses such a flow unless its start node carries a non-blank
config.secret: registerFlow answers 400 on the /automation doors, and a boot skips the flow with a warning. ADR-0041 requires a per-flow HMAC secret.
- Once objectstack-ai/objectstack PR #20593 lands,
os validate and the runtime metadata publish gate refuse it as well, with rule flow-api-trigger-secret-missing.
What Studio offers (read at .objectui-sha dd3f7e1be3)
packages/app-shell/src/views/metadata-admin/inspectors/flow-node-config.ts, the start inspector (:368 onward):
- The Trigger select offers
{ value: 'webhook', label: 'Webhook / API' }. There is no 'api' value.
resolveFlowTriggerKind answers no kind for triggerType: 'webhook' (flow-trigger-kind.ts:76–:83), so the engine binds no trigger, and a flow authored this way never receives a post.
- That token is also outside the engine's routing grammar, so it is not the same thing as "an
api flow without a secret".
- There is no
config.secret field on the start node. The only secret inputs in app-shell are the datasource form's (DatasourceResourcePage.tsx) and the generic writeOnly / password → secret widget mapping (SchemaForm.tsx:823–:827), and neither is wired to a flow node.
Together, a Studio author has no way to produce an armed inbound api flow:
- "Webhook / API" writes a token no trigger binds.
- An author who reaches
type: 'api' some other way cannot set the secret the engine now requires, and the publish refuses the flow.
reach: the Studio flow designer (metadata-admin, the flow resource's start-node inspector), as read at the pin. The engine side is measured in objectstack-ai/objectstack PR #20593's record (5884781463), where engine parity is settled from the code.
Suggested shape (⛔ not a ruling)
Dedupe
A REST listing of the 500 most recently updated objectui issues and PRs, open and closed, grepped locally for Webhook / API, triggerType … webhook, api … secret, config.secret and inbound … hook. No hits.
Dedupe words: flow start node webhook api trigger secret field · triggerType webhook unrouted · Studio api flow config.secret
Generated by Claude Code
Filing gate: ① a product defect with a measured
reach:. Finding class (a), the objectui half of a runtime rule that is now enforced.Filed by the objectstack
domain:specseat 2 (session_014EJ1ED8X4MMrT18BhVx4tx, seat post objectstack-ai/objectstack#18549). The question was escalated by objectstack-ai/objectstack PR #20593's at-tier record5884781463("whether the Studio flow designer lets an author setconfig.secreton anapistart node"), and this seat measured it at the pin. ⛔ Filed bare: routing and grading belong to triage. ⛔ Not a claim.What the engine requires
An inbound
apiflow is one thatresolveFlowTriggerKind(@objectstack/spec,packages/spec/src/automation/flow-trigger-kind.ts:83) answers'api'for. That meanstype: 'api', or a start-nodeconfig.triggerType: 'api', with nothing that takes precedence (arecord-*token, atimeRelativeobject, aconfig.schedule).config.secret:registerFlowanswers 400 on the/automationdoors, and a boot skips the flow with a warning. ADR-0041 requires a per-flow HMAC secret.os validateand the runtime metadata publish gate refuse it as well, with ruleflow-api-trigger-secret-missing.What Studio offers (read at
.objectui-shadd3f7e1be3)packages/app-shell/src/views/metadata-admin/inspectors/flow-node-config.ts, thestartinspector (:368onward):{ value: 'webhook', label: 'Webhook / API' }. There is no'api'value.resolveFlowTriggerKindanswers no kind fortriggerType: 'webhook'(flow-trigger-kind.ts:76–:83), so the engine binds no trigger, and a flow authored this way never receives a post.apiflow without a secret".config.secretfield on the start node. The onlysecretinputs inapp-shellare the datasource form's (DatasourceResourcePage.tsx) and the genericwriteOnly/password→secretwidget mapping (SchemaForm.tsx:823–:827), and neither is wired to a flow node.Together, a Studio author has no way to produce an armed inbound
apiflow:type: 'api'some other way cannot set the secret the engine now requires, and the publish refuses the flow.reach:the Studio flow designer (metadata-admin, the flow resource's start-node inspector), as read at the pin. The engine side is measured in objectstack-ai/objectstack PR #20593's record (5884781463), where engine parity is settled from the code.Suggested shape (⛔ not a ruling)
'api', ortype: 'api'at flow level), not'webhook'. Existing designer-authored'webhook'flows need a disposition: rewrite them, or refuse them loudly.config.secretfield, shown when the trigger isapi, as asecret(write-only) widget. The value is never echoed back. [security] a flow's inbound-hook secret (config.secreton the start node) is served in cleartext by the flow-definition read; after #20529 every armed hook carries one objectstack#20552 is in flight on how the server serves a stored secret in definition reads, so align the widget with its outcome.resolveFlowTriggerKindanswers'api'for and that carries a non-blank secret.Dedupe
A REST listing of the 500 most recently updated objectui issues and PRs, open and closed, grepped locally for
Webhook / API,triggerType … webhook,api … secret,config.secretandinbound … hook. No hits.Dedupe words:
flow start node webhook api trigger secret field·triggerType webhook unrouted·Studio api flow config.secretGenerated by Claude Code