• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

bleedingdeacons / reach / 34299400352
86%

Build:
DEFAULT BRANCH: main
Ran 09 Sep 2026 01:32AM UTC
Jobs 1
Files 94
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

09 Sep 2026 01:29AM UTC coverage: 86.498% (+0.08%) from 86.416%
34299400352

push

github

web-flow
fix: move the reset token out of the URL, guard the session token, throttle call requests (#115)

Three findings from the security review.

F9. PasswordResetMailer sends /reach/set-password?token=…, so the token sat
in the address bar and browser history for the life of the page and would
ride along in the Referer of anything that page linked out to. ResetTokenCookie
follows core's own pattern for reset links: read the token on arrival, put it
in a short-lived HttpOnly cookie scoped to that one page, redirect to the bare
URL. A redirect replaces the history entry rather than adding to it.

What it does not fix, and the review overstated: the emailed link still has
to carry the token, so the first request is still one line in the access log.
Nothing that keeps a link clickable avoids that, and core does not either.
Removing it entirely means not putting a token in a URL at all, which is what
Fellowship does — available to it because there is an app to type a code into.

F11. GET /reach/v1/session returns the token every cookie-authenticated write
must present, reasoning in a comment that "a cross-site caller cannot read the
response". True of a genuinely cross-*site* caller, whose request the
SameSite=Lax cookie never reaches. Untrue of a sibling subdomain: same-site
for the cookie, and core's rest_send_cors_headers() reflects any Origin back
with Access-Control-Allow-Credentials, so the browser lets it read the body.
With one host under the registrable domain an attacker could take the token
and forge every cookie-authenticated write in the plugin.

SameOriginOnly refuses that. An absent Origin is allowed: browsers omit it on
same-origin GETs and non-browser callers send none, so refusing on absence
would break curl, the handsets and monitoring while stopping nothing — the
attack needs a browser, and a browser sending a cross-origin credentialed
request always sets the header. A refusal answers as an unauthenticated
session rather than an error, so th... (continued)

6323 of 7310 relevant lines covered (86.5%)

15.07 hits per line

Coverage Regressions

Lines Coverage ∆ File
2
98.32
0.03% reach/reach/src/Rest/NearestMembersController.php
1
98.59
0.13% reach/reach/src/Rest/CallRequestController.php
Jobs
ID Job ID Ran Files Coverage
1 34299400352.1 09 Sep 2026 01:32AM UTC 94
86.5
GitHub Action Run
Source Files on build 34299400352
  • Tree
  • List 94
  • Changed 3
  • Source Changed 0
  • Coverage Changed 3
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #34299400352
  • 8fee0549 on github
  • Prev Build on main (#34297150596)
  • Next Build on main (#34347179136)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc