• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

bleedingdeacons / hand / 34349653615
93%

Build:
DEFAULT BRANCH: main
Ran 09 Sep 2026 12:12PM UTC
Jobs 1
Files 17
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

09 Sep 2026 12:12PM UTC coverage: 92.769%. Remained the same
34349653615

push

github

web-flow
fix: close the backup, keychain and cleartext holes from the September review (#52)

* fix: stop Android backing the alert history up to Google Drive

The manifest said allowBackup="true", and AlertHistoryStore writes up to
500 alerts as unencrypted JSON into FileSystem.AppDataDirectory - which
is exactly what Android Auto Backup collects. A night's callback records
for an AA helpline, names and numbers and whatever a caller said, were
therefore uploaded to the responder's Google account and restored onto
whatever handset that account next signed into.

AlertHistory's own documentation says a handset taken off the rota
should not leave a readable record of a night's callbacks behind it.
That was true of uninstall and false of backup.

Backup also carried the SecureStorage-backed device token and payload
key, which would reconstitute a working Reach enrolment on a device the
intergroup never enrolled.

Link has had allowBackup="false" and the reasoning written down since it
was built; this is that decision carried across, with the comment
rewritten for what Hand actually stores.

* fix: keep iOS keychain items on the handset that wrote them

SharedKeychain wrote the shared payload key with AfterFirstUnlock, and
neither MauiProgram set SecureStorage.DefaultAccessible, whose own
default is the same. AfterFirstUnlock items are included in encrypted
device backups and can be restored onto a different device, so a
restored backup reconstituted a working device token and the key
material to read alerts on a handset the intergroup never enrolled.

AfterFirstUnlockThisDeviceOnly has identical unlock semantics - a push
arriving on a locked phone still reads the key, which is the reason
AfterFirstUnlock was chosen - and excludes the item from migration. It
is the iOS counterpart of allowBackup="false" on Android.

Existing entries keep the attribute they were written with, so a handset
enrolled before this change follows at its next enrolment.

* fix: require HT... (continued)

1360 of 1466 relevant lines covered (92.77%)

1292.26 hits per line

Jobs
ID Job ID Ran Files Coverage
1 34349653615.1 09 Sep 2026 12:12PM UTC 17
92.77
GitHub Action Run
Source Files on build 34349653615
  • Tree
  • List 17
  • Changed 2
  • Source Changed 0
  • Coverage Changed 2
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #34349653615
  • 829fa67d on github
  • Prev Build on main (#34349258536)
  • Next Build on main (#34362867640)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc