• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

bcgov / digital-trust-common-service / 31819966187
87%

Build:
DEFAULT BRANCH: main
Ran 14 Aug 2026 04:35PM UTC
Jobs 1
Files 138
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

14 Aug 2026 04:34PM UTC coverage: 88.282% (+0.6%) from 87.726%
31819966187

push

github

web-flow
feat(auth): AU-04 scope-based access control (#37) (#166)

* feat(auth): AU-04 scope-based access control (#37)

Implement ScopeGuard with @RequireScopes/@RequireRoles, tenants:admin
implicit grant, platform-admin bypass, and 403 INSUFFICIENT_SCOPE responses.
Add role_scope seed migration, oauth_client.roles for machine platform
clients, architecture scope catalog migration, and admin route protection.

Stacked on feat/AU-03-jwt-validation-guard (PR #163).

Co-authored-by: Cursor <cursoragent@cursor.com>

* test(auth): prove @RequireScopes via integration route; defer user scope issuance to AU-02

Add integration-only ScopeCheckIntegrationModule with @RequireScopes
credentials:offer tests (403, 200, tenants:admin implicit grant). Fix
RequireScopes/RequireRoles decorator spec metadata lookup. Document that
role_scope → JWT scope for user tokens is deferred to AU-02 #35.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(auth): wire RoleScopeRepository and oauth_client.roles API

Address AU-04 review gaps: make RoleScopeRepository injectable with tests,
expose roles on OAuth client create/update/response, and document admin's
deliberate full Level 2+3 seed (including hold/revoke).

Co-authored-by: Cursor <cursoragent@cursor.com>

* test(auth): bring AU-04 touched files to 100% line coverage

Cover RoleScope/oauth-client roles update paths, empty required-scopes,
auth barrel re-exports, OAuthClient Tenant relation metadata, and the
empty OIDC_COOKIE_KEYS edge case.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(auth): format RoleScopeRepository empty-array assertion

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(auth): harden ScopeGuard and OAuth client roles

Return 401 when ScopeGuard runs without auth context, allowlist
oauth_client roles, and require client_credentials-only when roles
are set. Soften Swagger examples and trim RoleScopeModule comment.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: C... (continued)

1436 of 1791 branches covered (80.18%)

Branch coverage included in aggregate %.

118 of 118 new or added lines in 16 files covered. (100.0%)

2685 of 2877 relevant lines covered (93.33%)

9.35 hits per line

Jobs
ID Job ID Ran Files Coverage
1 31819966187.1 14 Aug 2026 04:35PM UTC 138
88.28
GitHub Action Run
Source Files on build 31819966187
  • Tree
  • List 138
  • Changed 14
  • Source Changed 14
  • Coverage Changed 13
Coverage ∆ File Lines Relevant Covered Missed Hits/Line Branch Hits Branch Misses
  • Back to Repo
  • Github Actions Build #31819966187
  • c4d286cf on github
  • Prev Build on main (#31602982875)
  • Next Build on main (#32156312903)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc