• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

erlef / oidcc / 351
92%

Build:
DEFAULT BRANCH: main
Ran 30 Aug 2026 01:07AM UTC
Jobs 1
Files 19
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

30 Aug 2026 01:06AM UTC coverage: 92.091% (+0.006%) from 92.085%
351

push

github

web-flow
Merge commit from fork

An ID token that was encrypted without being signed was accepted as fully
validated, so anyone holding the RP's public encryption key could mint a token
with an arbitrary `sub`. The spec requires a Nested JWT: "If the ID Token is
encrypted, it MUST be signed then encrypted" (OpenID Connect Core 1.0, section
2). JARM section 2.2 says the same, and that path is reachable through the
browser.

Fixes CVE-2026-75759 / GHSA-533g-4vf3-xwrj

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>

3 of 3 new or added lines in 2 files covered. (100.0%)

1176 of 1277 relevant lines covered (92.09%)

72.25 hits per line

Jobs
ID Job ID Ran Files Coverage
1 351.1 30 Aug 2026 01:07AM UTC 19
92.09
GitHub Action Run
Source Files on build 351
  • Tree
  • List 19
  • Changed 2
  • Source Changed 2
  • Coverage Changed 2
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • 5f62fbcc on github
  • Prev Build on main (#350)
  • Next Build on main (#352)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc