#782 HIGH: Secret cache TTL too long at 1 hour

closed high Created 2026-01-02 03:32 · Updated 2026-01-02 06:26

Description

Edit
SecretManager uses 1-hour TTL for secret cache. If a secret is rotated in Vault, workflows use stale credentials for up to 1 hour. For airport operations, compromised API keys remain in use. Location: engine/services/secret_manager.py:293-294. Fix: Reduce TTL to 300 seconds.

Comments

Loading comments...

Context

Loading context...

Audit History

View All
Loading audit history...