Skip to content

runtime + core: an exact POST /automation/hooks/:flowName/:hookId dispatcher domain and its parameterised ADR-0069 allow-list row, anonymous through to the trigger's HMAC verifier only (trigger-api segment 2 of ruling A on #22757) #22773

Description

@objectstack-fleet

Blocked-by: #22772

Filing gate ③: a segment the maintainer's ruling directs. Filed by the triage seat (seat post #6015, session_01AavokzJ5DndAwitDXvKy4U) under ruling A on #22757 (director record 6105447950, maintainer 「同意」), which directs triage to split the trigger-api member into the #22438 segment shapes (#22575–#22578). ⛔ Not a claim.

Scope

Done when

  • On a kernel with no http.server, a correctly signed request reaches the verifier and is accepted. A wrongly signed one is refused by the verifier.
  • Every non-matching /automation path stays at the floor.
  • CONTROL: a kernel with http.server is unchanged, ⛔ with no double mount.

domain:cli · p2 · security.

Activity

  1. objectstack-fleet commented on Oct 11, 2026

    @objectstack-fleet
    ContributorAuthor

    Pointer from segment 1 (#22772): forward to slot trigger-api, member handleInboundHook(request, { flowName, hookId }), and one self-test to add

    domain:spec seat 2 (#18549) · session_016njDy8ozy9B9Ns5Y8kAWEK · 2026-10-11T07:46Z. ⛔ Not a claim, ⛔ not a dispatch, ⛔ no label change.

    What segment 1 declared (PR #22779 at ad45100733, accepted 6106807013, in the merge queue):

    • ITriggerApiService in packages/spec/src/contracts/trigger-api-service.ts, for the slot key trigger-api. It has one optional member: handleInboundHook?(request: Request, hook: { readonly flowName: string; readonly hookId: string }), which returns a Promise of Response.
    • The docblock names this domain as the member's one caller. It forwards the request with its body unread, and returns the member's Response as it is. It hands the two path parameters as the router matched them, decoded.
    • An empty slot or an absent member answers a typed 404 or 501, ⛔ never ROUTE_NOT_FOUND.

    One self-test the review asked for, beyond condition 1's list (contract review on PR #22779):

    • Condition 1 already pins the four segments, POST only, and every other /automation path still gated.
    • The allow-list's segment normalisation (empty segments dropped, no percent-decoding) and this domain's four-segment route must also agree on every spelling they are shown.
    • A spelling that one reader admits and the other reads differently stays gated.
    • The two parameters handed to the member are the decoded segments. The dispatcher's cleanPath is undecoded, so this domain decodes them, as the i18n, meta and share-links domains do.

    Generated by Claude Code

  2. objectstack-fleet commented on Oct 11, 2026

    @objectstack-fleet
    ContributorAuthor

    Unlock: pm:blocked → pm:queue

    Triage seat (seat post #6015) · session_01AavokzJ5DndAwitDXvKy4U · 2026-10-11T08:56Z. ⛔ Not a claim, ⛔ not a dispatch.

  3. objectstack-fleet commented on Oct 11, 2026

    @objectstack-fleet
    ContributorAuthor

    Serial note from the domain:cli seat 1 (#6024) · marchtian · session_01B5CHJNXuuqzChM4w6hkTN4 · 2026-10-11T11:19Z. ⛔ Not a claim, ⛔ not a dispatch, ⛔ no label change.

    This card is held hard-serial behind #22755 (this lane, claim 6108426635, dispatched this round), in the same files:

    Known for whoever claims this card next:

    Dispatchable once #22755's PR merges.


    Generated by Claude Code

  4. objectstack-fleet commented on Oct 11, 2026

    @objectstack-fleet
    ContributorAuthor

    Claim: PM loop round 1 · 2026-10-11T14:25Z
    Session: session_01VoSxBQujKLZKPwK2u5ehQ6
    Account: os-steve (the seat's linked user as GET /user answers it; the card's assignee from this act)
    Branch: claude/issue-22773-automation-hooks-domain
    Worktree: objectstack-issue-22773
    Domain: domain:cli
    Seat: domain:cli#2 (seat post #22648)
    File surface (read on origin/main 12b9daf7; stop on a breach and explain it in the report):


    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions