TeamsChannelAdapter::post() (#2128) reads the Bot Framework bearer token straight from $configuration['accessToken'] (lib/Intake/Adapter/TeamsChannelAdapter.php:306). Nothing on the Teams path resolves a credentialRef. Yet docs/administrators/teams-intake.md configures "credentialRef": "teams-connector" (:33) and says the token is "resolved through credentialRef the way every other outbound credential is" (:80).
Consequences:
- An operator who follows the doc gets "The Teams source holds no connector access token.", so replies never send.
- The only working setup is to paste the bearer token into
configuration.accessToken. That path is not in lib/Settings/register.d/99-source-nested-auth-writeonly.json, whose list is exact paths, so the token renders in cleartext on every read of the source object: admins via the generic OpenRegister API and exports, and anyone the source read rule is ever delegated to.
lib/Intake/Adapter/MessagingChannelAdapter.php:211 has the same read (pre-existing, #2055).
Done when
Review thread: #1983 (comment)
TeamsChannelAdapter::post()(#2128) reads the Bot Framework bearer token straight from$configuration['accessToken'](lib/Intake/Adapter/TeamsChannelAdapter.php:306). Nothing on the Teams path resolves acredentialRef. Yetdocs/administrators/teams-intake.mdconfigures"credentialRef": "teams-connector"(:33) and says the token is "resolved throughcredentialRefthe way every other outbound credential is" (:80).Consequences:
configuration.accessToken. That path is not inlib/Settings/register.d/99-source-nested-auth-writeonly.json, whose list is exact paths, so the token renders in cleartext on every read of the source object: admins via the generic OpenRegister API and exports, and anyone thesourceread rule is ever delegated to.lib/Intake/Adapter/MessagingChannelAdapter.php:211has the same read (pre-existing, #2055).Done when
credentialRefvia the broker, orconfiguration.accessTokenis added tox-openregister-writeonly-paths, with a fragment version bump so existing installs re-import it;teams-intake.mddescribes the mechanism that actually works.Review thread: #1983 (comment)