• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

bleedingdeacons / hand / 34385128918
93%

Build:
DEFAULT BRANCH: main
Ran 09 Sep 2026 05:48PM UTC
Jobs 1
Files 18
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

09 Sep 2026 05:48PM UTC coverage: 92.975% (+0.03%) from 92.943%
34385128918

push

github

web-flow
fix: cap the inflate, scope the intent filter, and invert the dev-credentials default (#59)

* fix: cap how far a pushed payload may inflate

Inflate finished with gzip.CopyTo into an unbounded MemoryStream. It now
copies through a fixed buffer with a running total and abandons past
512KB, which is far above any real alert - Reach sends a handful of
short strings.

Here that is belt and braces: the GCM tag is verified first with a key
only the handset and Reach hold, so a forged payload never reaches the
inflate. Link has the same code and no such guarantee, because its
content key is wrapped to a public key anyone can mint against. The cap
goes in both so the weaker one cannot quietly drift.

Overflow returns null, which needs no new handling from callers - "will
not open" was already one outcome.

* fix: scope the OAuth callback intent filter to hand://auth

The exported callback activity declared only DataScheme, so it matched
all of hand:// rather than the one path the app answers on. Link has
always declared both halves.

ReachClient gains a CallbackHost constant alongside CallbackScheme, so
the filter and the redirect URL keep coming from one place.

Defence in depth rather than the defence: a custom scheme can be claimed
by another app either way, and what travels the redirect is a one-time
code that expires and is spent over TLS from the app's own process,
never a token.

* fix: make the safe build the default one for dev credentials

UseDevCredentials defaulted to true, so a release package built anywhere
but CI embedded devsettings.json - which holds a live Better Stack
source token - unless whoever ran the build remembered
-p:UseDevCredentials=false.

Nothing leaked this way: the file is git-ignored and untracked, and all
five CI build sites pass the flag. What was wrong was the polarity. The
safe path should not be the one you have to remember.

It now defaults to false and local development opts in with
-p:UseDevCredentials=true. The CI f... (continued)

1403 of 1509 relevant lines covered (92.98%)

1256.01 hits per line

Coverage Regressions

Lines Coverage ∆ File
39
76.24
0.0% Services/ReachClient.cs
2
96.61
0.46% Models/AlertPayloadCipher.cs
Jobs
ID Job ID Ran Files Coverage
1 34385128918.1 09 Sep 2026 05:48PM UTC 18
92.98
GitHub Action Run
Source Files on build 34385128918
  • Tree
  • List 18
  • Changed 2
  • Source Changed 0
  • Coverage Changed 2
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #34385128918
  • 687e5847 on github
  • Prev Build on main (#34380338160)
  • Next Build on main (#34411741967)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc