fix(workspace): block Hermes custom provider bypass #1863
Reference in New Issue
Block a user
Delete Branch "fix/hermes-platform-proxy-guard"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Tests
Security context
This makes the control plane enforce the platform proxy boundary instead of relying on template/runtime discipline alone.
Approved — blocks Hermes direct-provider bypass secrets in platform-managed mode across secret writes and workspace creation; targeted regression coverage included.
Security review passed. Scope is limited to blocking Hermes custom-provider escape-hatch keys in platform-managed mode across create, workspace secret set, and global secret set. No new endpoints, dependencies, raw SQL interpolation, or secret material introduced. Regression test covers the rejected workspace secret path; existing provisioning tests cover the platform-managed env mode boundary.
Security review passed.
/security-recheck