• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

bleedingdeacons / fellowship / 34699251165
90%

Build:
DEFAULT BRANCH: main
Ran 12 Sep 2026 02:29PM UTC
Jobs 1
Files 58
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

12 Sep 2026 02:25PM UTC coverage: 90.871% (+0.07%) from 90.806%
34699251165

push

github

web-flow
feat: require a credential to rotate a device key (#20)

A live bearer token was enough to substitute the public key on a device
row. Because the inbox seals from plaintext on every fetch, to whatever
key the row holds, that one call was sufficient to have every message
inside the retention window re-sealed to a key of the caller's choosing.
The handset keypair offered no resistance at all: it is never used to
authenticate anything.

So rotation now needs a credential as well as the token, by any of the
three routes enrolment accepts -- a Google code, an Apple state and ID
token, or an email and password. The route is rate-limited on the same
bucket as the exchange.

And the credential has to belong to the member the handset does.
Without that check the attack simply puts on a hat: capture a token,
prove your own identity, substitute the key on somebody else's phone.
Addresses are compared the way MemberGate resolves them, lowercased and
trimmed, so a capitalisation difference between a provider and Unity
cannot refuse somebody their own handset.

Proof of possession of the old key would be the tidier control and
cannot work here: this route exists precisely because that key is gone.

The credential is checked before the public key is parsed, which moved
two existing tests -- they are about the key, so they now carry a
credential to reach it.

BREAKING for the app. Link's Settings recovery posts only a public key
and will be refused until it sends one. Do not merge before Link ships
the other half.

3235 of 3560 relevant lines covered (90.87%)

6.45 hits per line

Coverage Regressions

Lines Coverage ∆ File
14
96.65
0.05% fellowship/fellowship/src/Rest/DeviceAuthController.php
Jobs
ID Job ID Ran Files Coverage
1 34699251165.1 12 Sep 2026 02:29PM UTC 58
90.87
GitHub Action Run
Source Files on build 34699251165
  • Tree
  • List 58
  • Changed 1
  • Source Changed 0
  • Coverage Changed 1
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #34699251165
  • 76459f5e on github
  • Prev Build on main (#34694062992)
  • Next Build on main (#34706978106)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc