Temporal stores workflow inputs, including members' names and sign-in identifiers, in plain text #162

Open
opened 2026-10-05 02:10:05 +00:00 by cgalo5758 · 0 comments
Owner

What a person cannot do today

An operator cannot keep members' personal data out of Temporal in readable form. The console's Temporal client sets no payload codec, so every workflow and activity input and result is stored as plain JSON in the workflow history. The FedWiki site-creation workflow's input, for example, carries the owner's display name, their sign-in identifier (the OIDC subject) and the site's domain (internal/integrations/fedwiki/workflows/workflow.go:68-76). Anyone who can read the namespace, through the Temporal UI, the Temporal CLI or Temporal's database, can read them.

What they should be able to do

Run the console with workflow payloads encrypted before they leave the process, under a key the deployment supplies, and still read decoded payloads when debugging.

Why it matters

Temporal keeps each workflow's history for the namespace's retention period, and its database is backed up and accessed separately from the console's own. Temporal's guidance is to encrypt sensitive payloads with a payload codec rather than store them in plain text.

Where

  • internal/workflows/client.go, where the console dials Temporal. The Go SDK wraps the default data converter with a codec through converter.NewCodecDataConverter.
  • Every workflow and activity input and result that carries personal data. Only the FedWiki create input has been checked so far.
  • The Temporal UI in the test stack, which shows encoded payloads unless it is pointed at a codec server.

Done when

  • Workflow and activity payloads are encrypted under a key the deployment supplies, and rotating the key does not strand running workflows.
  • Workflow IDs, search attributes and failure messages carry no personal data, since a codec does not encrypt them by default.
  • An operator can read decoded payloads while debugging, through a codec server that checks who is asking.
  • The deployment docs say how to set the key and the codec server.
### What a person cannot do today An operator cannot keep members' personal data out of Temporal in readable form. The console's Temporal client sets no payload codec, so every workflow and activity input and result is stored as plain JSON in the workflow history. The FedWiki site-creation workflow's input, for example, carries the owner's display name, their sign-in identifier (the OIDC subject) and the site's domain (`internal/integrations/fedwiki/workflows/workflow.go:68-76`). Anyone who can read the namespace, through the Temporal UI, the Temporal CLI or Temporal's database, can read them. ### What they should be able to do Run the console with workflow payloads encrypted before they leave the process, under a key the deployment supplies, and still read decoded payloads when debugging. ### Why it matters Temporal keeps each workflow's history for the namespace's retention period, and its database is backed up and accessed separately from the console's own. Temporal's guidance is to encrypt sensitive payloads with a payload codec rather than store them in plain text. ### Where - `internal/workflows/client.go`, where the console dials Temporal. The Go SDK wraps the default data converter with a codec through `converter.NewCodecDataConverter`. - Every workflow and activity input and result that carries personal data. Only the FedWiki create input has been checked so far. - The Temporal UI in the test stack, which shows encoded payloads unless it is pointed at a codec server. ### Done when - Workflow and activity payloads are encrypted under a key the deployment supplies, and rotating the key does not strand running workflows. - Workflow IDs, search attributes and failure messages carry no personal data, since a codec does not encrypt them by default. - An operator can read decoded payloads while debugging, through a codec server that checks who is asking. - The deployment docs say how to set the key and the codec server.
cgalo5758 added the
kind
enhancement
area/opssecurityprivacy
labels 2026-10-05 02:10:05 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: wiki-cafe/member-console#162