Melvin StroblandClaude Opus 5 ca7a16c8bc Guard webhooks with a per-hook secret, and allow rotating the app key
Trigger hooks are mounted unauthenticated because devices cannot present
a JWT. They now take a secret as a trailing path segment, so a device
needs one URL and no header support. The value never enters the
registered route, only a {secret} template, and is compared with
compare_digest; a mismatch is a bare 404 so the endpoint does not
confirm which hooks exist. Pointing the parameter at the encrypted store
keeps the literal out of flow.json. Hooks without a secret keep working
and now raise a validation issue saying so.

Rotating SECRET_KEY made the stored secrets unreadable for good, since
the Fernet key derives from it. scripts/rotate_secret_key.py re-encrypts
with the new key and refuses if the old one does not decrypt. Now that
recovery exists, an unreadable store fails loudly instead of coming back
empty and leaving flows short of credentials with no visible cause.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KkmeRiyeYmVZqJVwuyHq9o
2026-08-15 21:19:32 +02:00
2026-02-03 21:43:09 +01:00
2026-02-03 21:43:09 +01:00
2026-02-03 21:43:09 +01:00
2026-02-03 21:43:09 +01:00
2026-02-03 21:43:09 +01:00
2026-02-03 21:43:09 +01:00
up
2026-08-15 14:48:16 +02:00
2026-02-03 21:43:09 +01:00

Fluksio App

Fluksio has the goal to build a revolutionary system to tackle any sort of automation challenge.

The core of Fluksio: a node-based, test-driven automation software built to scale. This repo holds the FastAPI backend, the flow engine, and the dashboard SPA. It is served on app.${DOMAIN} (SPA) and api.${DOMAIN} (API); the marketing site lives in the sibling index repo.

Layout

backend/        FastAPI + SQLModel + Alembic + Postgres
  app/flow/     the flow engine (nodes, pipeline, state backends, controller)
frontend/       React 19 + TanStack Router + Tailwind 4 + shadcn/ui
docker/         compose.yml → compose.dev.yml → compose.local.yml (+ compose.traefik.yml)
scripts/        generate-client.sh, test.sh

Getting started

Normally driven from the workspace root (make init once, then make dev). Standalone:

make install       # uv sync + bun install
make dev-utils     # db, adminer, proxy, mailcatcher, prestart only
make dev-backend   # FastAPI on :8000, hot reload
make dev-frontend  # Vite on :5173
make test           # pytest + Playwright
make lint           # ruff + mypy + biome
make generate-client  # regenerate the frontend SDK from the OpenAPI schema

make help lists every target.

Documentation

  • ROADMAP.md — strategy and feature record
  • NOTEPAD.md — deferred work and findings
  • DESIGN.md — points at the workspace root's DESIGN-GUIDELINES.md
  • docs/architecture/ in the sibling docs repo — the requirement sources
S
Description
No description provided
Readme AGPL-3.0
7.1 MiB
Languages
Python 54%
TypeScript 42.6%
CSS 1.9%
HTML 0.5%
JavaScript 0.5%
Other 0.3%