Clear Filters
ID Title Status Priority Created Due Date Actions
#911 Token endpoint leaks caught exception text into client 500 responses (str(e) in details, f-string in raise)
EARS SPEC: - When a token endpoint fails, the API shall return a generic error code and message to t...
open high 2026-08-22 13:33 -
Edit
#851 Vault token VAULT_TOKEN_ADMIN is invalid - OIDC/SSO sign-in and circuit-breaker API are down in production
EARS SPEC: - When the Highway API cannot authenticate to Vault, the /api/v1/health circuit_breaker_d...
open critical 2026-08-22 01:50 -
Edit
#847 Encryption master key has an on-host env fallback next to the PostgreSQL data directory
EARS SPEC: - The Highway platform shall source the JSONB encryption master key from Vault only; if V...
open high 2026-08-03 20:47 -
Edit
#844 circuit-breakers 503: Vault password for resilient_circuit_db never applied to the postgres role
EARS SPEC: - When GET /api/v1/circuit-breakers is called by an authorized caller, the Highway API sh...
closed critical 2026-08-03 16:44 -
#842 Back-channel logout: accept identity logout_token, revoke Highway OIDC sessions
EARS SPEC: - When identity POSTs a logout_token to /api/v1/auth/oidc/backchannel-logout, the API sha...
closed high 2026-07-31 12:54 -
#840 Integrate RODMENA Identity (OIDC) as sign-in option for highway-dashboard
EARS SPEC: - When a user chooses 'Sign in with RODMENA ID', the Highway API shall run an authorizati...
closed medium 2026-07-31 10:55 -
#839 Upgrade auth to 3.0.0 (strict-default flip with grandfathering; client always raises)
EARS SPEC: - The Highway platform shall pin auth>=3.0.0 and deploy it with the migrations entrypoint...
closed high 2026-07-31 01:53 -
#838 Adopt key-backed users (auth rak_ API keys) per auth deprecation notice 2/2 (SPEC 0008)
EARS SPEC: - When auth 3.0.0 strict identity becomes default, every Highway authorization subject (u...
closed high 2026-07-31 00:50 -
#834 Upgrade auth lib to >=2.4.0 (auth 3.0.0 deprecation notice) + answer runflow RF-58 fix-notice
EARS SPEC: - The Highway platform shall pin the auth Python library to >=2.4.0 (the 3.0.0 migration ...
closed high 2026-07-30 23:26 -
#820 SECURITY: /api/v1/activities listed all tenants' activities (no tenant filter)
GET /api/v1/activities built its SQL with WHERE 1=1 and never filtered by tenant: any tenant's API k...
closed critical 2026-07-12 01:28 -
#257 SECURITY: API Key rotation did not deactivate old keys
Critical security vulnerability discovered in API key rotation: **Issues Found:** 1. Rotation kept ...
closed high 2025-12-04 16:08 -