• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

ilpanich / axiam-php-sdk / 34778547807
95%

Build:
DEFAULT BRANCH: main
Ran 13 Sep 2026 07:44PM UTC
Jobs 1
Files 339
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

13 Sep 2026 07:43PM UTC coverage: 94.67% (+0.001%) from 94.669%
34778547807

push

github

web-flow
F-1 (PHP): certificates.signCsr and the WebAuthn setup/register pair (contract 1.45) (#68)

Re-vendors CONTRACT.md, openapi.json, management-registry.json and proto/
from ilpanich/axiam@3d5b279 (contract 1.45) and lands this SDK's share of
F-1 against the EXECUTED record for C-1 and M-3 in
mfa-first-login-and-csr-issuance-plan.md, not the plan's draft.

C-1 (mechanical): scripts/gen_management.py --check found the registry
already at 160 operations (159 -> 160) and regenerated
CertificatesApi::signCsr(), the new SignCertificateCsrRequest model, and
the two generated test suites (surface + round-trip). No hand-written
model was needed -- the generator already omits `subject`/`key_algorithm`
(read off the CSR server-side) and there is no key field anywhere on the
request or on the response, which is the *existing* Certificate model per
CONTRACT.md §27.5's new sentence, never GeneratedCertificate. Added a
hand-written test (ManagementSemanticsTest) that reflects over a decoded
Certificate and asserts no property name contains "privatekey" and no
property value is a Sensitive -- a generator regression pointing signCsr
at GeneratedCertificate would fail it even though the generated surface
test would not (it only checks the fields present in one fixture).

M-3 (mirror): two JSON-bridge helpers beside webauthnRegisterStart/Finish.
webauthnSetupRegisterStart/Finish take a setup token in the body as their
ONLY credential (CONTRACT.md §24.1, contract 1.45) and, per this task's
binding rule, this SDK must never attach its own session on top of it --
even when one is configured. That needed new machinery, not just two new
methods: AuthMiddleware gained a NO_SESSION_CREDENTIALS_OPTION per-request
flag that suppresses Authorization and X-CSRF-Token unconditionally
(X-Tenant-ID is unaffected -- routing context, not a credential, §5 rule
2), and AxiamClient::postWithoutSessionCredentials() sets it and routes
the request's cookies through a scratch CookieJar rather t... (continued)

109 of 113 new or added lines in 4 files covered. (96.46%)

9681 of 10226 relevant lines covered (94.67%)

21.76 hits per line

Uncovered Changes

Lines Coverage ∆ File
2
89.68
0.37% src/AxiamClient.php
2
90.48
src/Management/Models/SignCertificateCsrRequest.php
Jobs
ID Job ID Ran Files Coverage
1 34778547807.1 13 Sep 2026 07:44PM UTC 339
94.67
GitHub Action Run
Source Files on build 34778547807
  • Tree
  • List 339
  • Changed 4
  • Source Changed 4
  • Coverage Changed 3
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #34778547807
  • d265f79b on github
  • Prev Build on main (#34756471948)
  • Next Build on main (#34931960189)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc