• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

ilpanich / axiam-typescript-sdk / 32314889692
94%

Build:
DEFAULT BRANCH: main
Ran 19 Aug 2026 11:50PM UTC
Jobs 1
Files 48
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

19 Aug 2026 11:49PM UTC coverage: 92.547% (-2.4%) from 94.986%
32314889692

push

github

web-flow
feat(srp): SRP-6a login client (CONTRACT §23) + npm Trusted Publishing (#66)

* feat: SRP-6a client (§23), and the npm Trusted Publishing prerequisites

## SRP

`loginSrp` returns the same `LoginResult` as `login`, including the
`mfa_required` branch, so an application can switch a tenant to SRP without
touching its own code.

`src/core/srp.ts` is protocol only — no HTTP, no client, no session. That half
has to agree byte-for-byte with ten other language implementations, and
keeping it free of transport is what lets `test/core/srp.test.ts` replay the
vendored cross-language vectors with no server and no mock. All six reproduce
exactly, every intermediate included: k, v, A, B, u, S, K, M1, M2.

Notes on choices that were not obvious:

- The RFC 5054 moduli are embedded and never taken from the server: a
  server-supplied N is a server-supplied trapdoor. Their primality and
  safe-primality are asserted, because a transcription slip is a silent total
  break that a client/server round trip cannot catch — both sides share the
  same wrong constant.
- An unknown group or KDF raises NetworkError, never AuthError, and is never
  substituted. Substituting derives a different `x` and surfaces as "invalid
  password", sending a user off to reset a password that works.
- `hash-wasm` is a real dependency rather than optional: §23.3 rule 4 makes
  both KDFs mandatory and argon2id is what AXIAM's default policy asks for. It
  is imported lazily, so a consumer who never calls SRP does not pay the wasm
  payload at module-load time.
- The challenge request reuses `buildLoginBody` so tenant/org resolution
  cannot drift between the two login paths, then deletes `password` — it has
  no business on that request.

## npm Trusted Publishing

Three changes to the `publish` job, all marked `[TRUSTED PUBLISHING]`, in
response to the trusted publisher configured npm-side against this workflow:

1. An `environment:` line, commented out with instructions. If the npm
   config... (continued)

1197 of 1333 branches covered (89.8%)

Branch coverage included in aggregate %.

93 of 146 new or added lines in 3 files covered. (63.7%)

1895 of 2008 relevant lines covered (94.37%)

436.64 hits per line

Uncovered Changes

Lines Coverage ∆ File
48
3.53
src/rest/srp.ts
3
90.63
-9.38% src/rest/client.ts
2
94.26
src/core/srp.ts
Jobs
ID Job ID Ran Files Coverage
1 32314889692.1 19 Aug 2026 11:50PM UTC 48
92.55
GitHub Action Run
Source Files on build 32314889692
  • Tree
  • List 48
  • Changed 1
  • Source Changed 1
  • Coverage Changed 1
Coverage ∆ File Lines Relevant Covered Missed Hits/Line Branch Hits Branch Misses
  • Back to Repo
  • Github Actions Build #32314889692
  • 9d5d5c7b on github
  • Prev Build on main (#32243459862)
  • Next Build on main (#32343894567)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc