• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

bleedingdeacons / hand / 34362867640
93%

Build:
DEFAULT BRANCH: main
Ran 09 Sep 2026 02:20PM UTC
Jobs 1
Files 17
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

09 Sep 2026 02:19PM UTC coverage: 92.769%. Remained the same
34362867640

push

github

web-flow
fix: say which app is calling, on every outbound request (#54)

.NET sets no User-Agent of its own, so whatever the platform handler
defaults to is what goes out. On Android that is a bare

    Dalvik/2.1.0 (Linux; U; Android 16; SM-S926B Build/BP4A.251205.006)

which names the runtime and the handset model and says nothing about the
app. Every Hand handset was therefore indistinguishable in an access log
from any other Android process on the same network.

That anonymity turned out to cost more than diagnostics. An unidentified
Dalvik client polling a REST API on a fixed interval is the shape bot
protection scores worst, and on 2026-09-09 SiteGround's Anti-Bot AI
flagged one network's address on that profile: every HTTP client behind
it was served a JavaScript challenge page where the JSON should have
been. A native client cannot answer one, so the handsets got HTML into
System.Text.Json and sign-in never reached Google -- the browser leg
opens auth/device/start on Reach, which was challenged before the flow
started. Reach itself was healthy throughout; the requests never
arrived. The site returned 200 to the same URL from another address.

Three clients, because three exist. Both factories in MauiProgram cover
the Reach and Better Stack clients, and HeadlessAlerts builds its own
for the alerts/unreadable report -- it never touches the container, so
it inherits nothing and has to identify itself separately. It compiles
into no head but Android, hence the hardcoded platform there against
DeviceInfo elsewhere.

WHAT THIS IS NOT. It is not a defence against that challenge happening
again, and must not be read as one: the same host fingerprints the TLS
handshake (JA4), which no request header changes. The fix for an API
behind a browser challenge is the server exempting it. This is here so
the traffic is attributable, and so it is not sitting in the anonymous
bucket to begin with.

Version and platform come from AppInfo and DeviceInfo rather than a
liter... (continued)

1360 of 1466 relevant lines covered (92.77%)

1292.27 hits per line

Jobs
ID Job ID Ran Files Coverage
1 34362867640.1 09 Sep 2026 02:20PM UTC 17
92.77
GitHub Action Run
Source Files on build 34362867640
  • Tree
  • List 17
  • Changed 0
  • Source Changed 0
  • Coverage Changed 0
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #34362867640
  • dff8ce1d on github
  • Prev Build on main (#34349653615)
  • Next Build on main (#34365271848)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc