- Created daily log entries for May 13, 14, 18, 19, 20, and 21, capturing work done, findings, and next steps. - Established a daily logs index for easy navigation of daily notes. - Developed templates for daily logs, decisions, meeting notes, people, systems, and work items to standardize documentation. - Introduced base files for filtering and displaying various types of project knowledge, including daily notes, decisions, people, systems, work items, and workstreams. - Added maps for current work, fidelity apps, and fidelity domain to enhance project navigation and context.
1.5 KiB
1.5 KiB
type, project, status, ticket, title, systems, workstreams, people, related, updated, tags
| type | project | status | ticket | title | systems | workstreams | people | related | updated | tags | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| work-item | fidelity | backlog | PDIAP-11961 | Remediation of Exposed Secrets in XFlow iOS SDK - Request for Rotation/Invalidation |
|
|
|
|
2026-05-05 |
|
PDIAP-11961 - Remediation of Exposed Secrets in XFlow iOS SDK - Request for Rotation/Invalidation
Status
- Backlog item; not assigned yet.
- Jeff relayed that this is not a priority yet, but asked David to keep the details noted for future reference.
Context
- Related to the remaining Google API Key alerts not included in the previous
PDIAP-11962closure. - If key rotation or invalidation is required, David/XFlow likely needs backend support or clarification because Google API Key rotation is not owned directly by the XFlow iOS side.
Historical Slack Context
- October 2025 Slack context describes
PDIAP-11961as the request for rotation/invalidation of active exposed Google API keys. - The active Google API keys were documented as still valid/in use by the service, so they were intentionally separated from inactive-secret closure evidence.
PDIAP-11962was created as the second-phase closure story to run afterPDIAP-11961invalidation/rotation work completed.- Earlier investigation noted that the API key appeared in a service response and that GitHub was flagging the old commit where the key had been hard-coded and later removed.