• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

archetech / archon / 32413083312
87%

Build:
DEFAULT BRANCH: main
Ran 20 Aug 2026 08:19PM UTC
Jobs 1
Files 89
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

20 Aug 2026 08:15PM UTC coverage: 94.073%. Remained the same
32413083312

push

github

web-flow
fix: Drop the egress address filter, keep the scheme checks (#908)

* fix(didcomm): Remove the relay's egress guard rather than half-enforce it

The guard rejected non-https and private/loopback destinations unless
ARCHON_DIDCOMM_ALLOW_PRIVATE_EGRESS was set, but it matched hostnames with a
literal regex. `127.0.0.1.nip.io` resolves to loopback and walked straight
through it, as does any attacker-controlled DNS name pointing at a private
address or a mapped IPv6 form. It stopped honest same-host and LAN delivery
and not an attacker, so it bought nothing for what it cost.

Removed with its opt-in flag, which was itself unreachable: sample.env and the
design doc documented ARCHON_DIDCOMM_ALLOW_PRIVATE_EGRESS as an operator knob,
but docker/compose/didcomm.yml never passed it through, so in Docker it was
permanently false.

Egress is now explicitly unrestricted, and documented as such in the service
spec, sample.env and the design doc -- including the consequence, which the
old guard obscured: POST /deliver authenticates any *resolvable* DID, not only
a local identity, so anyone able to create a DID can make the relay POST bytes
of their choosing to any host it can reach. That is a deployment constraint
now, stated rather than implied by a check that did not hold.

The e2e no longer needs its allowPrivateEgress opt-in to deliver to its own
localhost relay, which is the honest case the guard was blocking.

lightning-mediator carries the same isPrivateHost pattern on its LNURL and
invoice paths and is deliberately untouched here: those guard a payment flow,
not a mailbox, and that is a separate decision.

Fixes #902
Refs #645

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix(didcomm): Keep the egress scheme check, drop the address filter

Follow-up on the previous commit, which removed both halves of the guard. Only
one half was ever doing work.

The address filter matched hostnames with a literal regex, so
`127.0.0.1.nip.io` -- or... (continued)

3773 of 4247 branches covered (88.84%)

Branch coverage included in aggregate %.

8433 of 8728 relevant lines covered (96.62%)

687.01 hits per line

Jobs
ID Job ID Ran Files Coverage
1 32413083312.1 20 Aug 2026 08:19PM UTC 178
95.09
GitHub Action Run
Source Files on build 32413083312
  • Tree
  • List 89
  • Changed 75
  • Source Changed 1
  • Coverage Changed 75
Coverage ∆ File Lines Relevant Covered Missed Hits/Line Branch Hits Branch Misses
  • Back to Repo
  • Github Actions Build #32413083312
  • 8cfde69a on github
  • Prev Build on main (#32401592846)
  • Next Build on main (#32420044363)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc