• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

SeaweedbrainCY / zero-totp / 26850636017
92%
main: 92%

Build:
Build:
LAST BUILD BRANCH: dependabot/pip/api/starlette-1.0.1
DEFAULT BRANCH: main
Ran 02 Jun 2026 10:02PM UTC
Jobs 1
Files 178
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

02 Jun 2026 10:01PM UTC coverage: 92.271% (-0.06%) from 92.327%
26850636017

push

github

SeaweedbrainCY
feat(api): If the detected Origin is likely a mobile app, tokens are also returned in the body

The Origin header is used to know if the origin app is capacitor or not. This header is spoofable, but only on a hijacked browser. Innocent user cannot have this modified without a compromised browser.
Attacker can spoof their own Origin header. In that case there is no sensitive information that isn't already transmitted in the SetCookies header.

It's more a precaution feature than a security feature

9 of 15 new or added lines in 1 file covered. (60.0%)

52 existing lines in 1 file now uncovered.

13609 of 14749 relevant lines covered (92.27%)

0.92 hits per line

Uncovered Changes

Lines Coverage ∆ File
6
89.99
-0.57% api/controllers.py

Coverage Regressions

Lines Coverage ∆ File
52
89.96
-0.57% controllers.py
Jobs
ID Job ID Ran Files Coverage
1 26850636017.1 02 Jun 2026 10:02PM UTC 266
61.55
GitHub Action Run
Source Files on build 26850636017
  • Tree
  • List 178
  • Changed 81
  • Source Changed 3
  • Coverage Changed 81
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #26850636017
  • 440742d4 on github
  • Prev Build on feat/add_ios_app (#26847366813)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc