Conversation
Arpanexe
reviewed
Sep 17, 2026
|
|
||
| Actions declared `client` or `any` do not receive private or protected settings, including when an `any` action is invoked on the server. Opening an action's compiled HTML in a browser does not provide protected values. See [App Actions V3](../core/app-actions-v3.md) for execution and integration requests. | ||
|
|
||
| Protected values are omitted from ordinary app responses and app-version snapshots. Restoring an app version preserves its current protected settings rather than restoring old credentials. Cloning an app does not provision credentials for the clone; configure them separately. |
Contributor
There was a problem hiding this comment.
This says cloning does not provision credentials, but the linked API clone path only removes protected __… and legacy _aiartifact_… settings. Ordinary editor-private keys are copied, including the _saml2 certificate example recommended later on this page. This could lead editors to assume those credentials were omitted. Could we clarify that only protected credentials are excluded and that _… settings are cloned?
Deploying fliplet-cli with
|
| Latest commit: |
e750b07
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://66e5e1c8.fliplet-cli.pages.dev |
| Branch Preview URL: | https://feature-dev-1719-server-inte.fliplet-cli.pages.dev |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updates the canonical App Actions V3, V3 App Settings Convention and Fliplet.App references to match the implementation. Covers visibility and trusted authors, explicit credential writes/status/deletion, server-only reads, rotation, HTTPS origins/limits, execution envelopes, safe logs and a complete integration example.
Regenerates the existing AI discovery indexes and capability catalog so Studio and other doc consumers can discover the same guidance. Documents compatibility for older Studio credential writes and the fixed execution-error messages. No extra documentation surface is introduced. Publish with the corresponding runtime; local doc edits alone do not change what deployed Studio fetches.
Jira: DEV-1719
Delivery and remaining verification
This is part of the agreed Studio V3 integration scope: private/protected settings in server actions, credential management, server HTTP calls, AI guidance and developer documentation. Deploy the compatible browser service before the API, then Studio; publish developer docs with the matching runtime. No tunnel, capabilities endpoint, enable flag or mandatory Lambda version pinning is included. No deployment or production credential migration has been performed.
The existing payload-to-HTML issue is separately tracked in DEV-2022; it is outside this change and is not a release prerequisite. Full authenticated builder scenarios remain unverified. Keep this PR in draft until the receiving developer has reviewed the implementation and remaining QA.
Test plan
Verification
cd docs && npm run check:docs.npm run test:unit.bundle exec jekyll build && node bin/copy-md-siblings.mjs. Existing Liquid warnings remain in unrelated pages.npm run check:v3-catalogreports an existingfliplet-service-workerentry absent from live assets. Catalog package names are unchanged from the base; this unrelated check is not passing.QA acceptance
API/core/app-actions-v3.html#server-api-integrations,API/v3/app-settings.htmlandAPI/core/app.html#settings. Check tables/code blocks, internal links and preserved anchors.any/clientdo not receive private/protected settings throughFliplet.App.Settings; permissions on separate REST endpoints are unchanged.Related PRs and documentation