• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

bleedingdeacons / reach / 34486565115
86%

Build:
DEFAULT BRANCH: main
Ran 10 Sep 2026 02:07PM UTC
Jobs 1
Files 95
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

10 Sep 2026 02:03PM UTC coverage: 86.402% (-0.007%) from 86.409%
34486565115

push

github

web-flow
feat: seal the alert payload for iOS as well as Android

The last plaintext path out of Reach. An Android push has carried one
field for a while now — `ciphertext`, and nothing beside it — while iOS
was sent the whole alert readable: title, body, reference and whatever
the raising plugin attached, both in the data block and repeated under
an `apns.payload.reach` key.

That exemption had a reason. The system draws an iOS lock screen from
the `aps` dictionary before any of Hand runs, so encrypting alone would
have put base64 in front of whoever was stood near the phone rather than
hiding anything. Closing it needed a notification service extension in
Hand, which now exists, is compiled, and is bundled into the iOS head.

So:

  * dataFor() loses its platform branch and seals for both.
  * aps gains `mutable-content: 1`, which is what launches the extension.
  * aps.alert carries a placeholder — "Reach alert" / "Open Hand for the
    details." — instead of the alert's own words. That is what a
    responder sees only if the extension never runs, so it has to be
    safe to show to a room and still worth waking up for.
  * The plaintext `apns.payload.reach` copy is gone. The sealed blob is
    put in the APNs payload explicitly rather than relying on FCM to
    merge the top-level data block; both land it in the userInfo
    dictionary the extension reads, and saying it here means the shape
    does not depend on a behaviour of FCM's that is documented but not
    ours.

An iOS handset with no usable payload key is now refused on exactly the
same terms as an Android one — null, logged as an error, visible on the
Sentinel dashboard — where before it would have been sent to regardless.
A responder fixes it by signing in again, which is the same recovery as
a lost token.

Deployable in either order with Hand's half. An older Hand build has no
extension, ignores mutable-content, and shows the placeholder; a handset
enrolled before this still holds the key it ... (continued)

6392 of 7398 relevant lines covered (86.4%)

15.29 hits per line

Jobs
ID Job ID Ran Files Coverage
1 34486565115.1 10 Sep 2026 02:07PM UTC 95
86.4
GitHub Action Run
Source Files on build 34486565115
  • Tree
  • List 95
  • Changed 1
  • Source Changed 0
  • Coverage Changed 1
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #34486565115
  • 1e886606 on github
  • Prev Build on main (#34392182184)
  • Next Build on main (#35540059982)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc