• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

ilpanich / axiam-python-sdk / 34778531440
99%

Build:
DEFAULT BRANCH: main
Ran 13 Sep 2026 07:44PM UTC
Jobs 1
Files 78
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

13 Sep 2026 07:42PM UTC coverage: 98.541% (-0.03%) from 98.573%
34778531440

push

github

web-flow
feat(pki,auth): sign-csr certificates, passkey-first-factor setup (contract 1.45) (#81)

The Python half of `claude_dev/mfa-first-login-and-csr-issuance-plan.md`'s
F-1 fan-out (§9): C-1 (`certificates.sign_csr`) and M-3
(`webauthn_setup_register_start`/`_finish`), re-vendored from
`ilpanich/axiam@3d5b279`.

**C-1 — `certificates.sign_csr` (CONTRACT.md §27, §27.5).** Entirely
mechanical: `scripts/gen_management.py` picked up the new registry entry
and the openapi.json's `SignCertificateCsrRequest` schema on its own —
no hand-written model was needed. `client.certificates.sign_csr(...)` on
both `AxiamClient` and `AsyncAxiamClient`, answering the existing
`Certificate`, not `GeneratedCertificate`: there is no key to return, and
§27.5's new sentence is explicit that a mandatory key field that is always
absent would be a type that lies about every value it holds. Added a
model round-trip test (`tests/management/test_semantics.py`) pinning that
`Certificate` carries no `private_key_pem` field at all, on top of what
the generator produced. Operation count moves 159 -> 160 across the same
24 namespaces; the generator updated that assertion in
`tests/test_management_surface_generated.py` itself.

**M-3 — a passkey or security key as the first factor at forced
enrolment (CONTRACT.md §24.1, §25.2 rule 2).** The WebAuthn twin of
`mfa_setup_enroll`/`mfa_setup_confirm`: `webauthn_setup_register_start`
and `webauthn_setup_register_finish`, on both clients, taking the
`setup_token` a `login()` `mfa_setup_required` outcome carries.

Both calls take no session, and the SDK must not attach its own even when
one is configured (§24.8) — this SDK is cookie-jar based, and
`httpx.Client.build_request()` is exactly where the shared jar (this
repo's Assumption A1) gets merged into every outgoing request, with no
per-call opt-out once it has run. Added a parallel send path instead of
reusing it: `_Session._credential_free_request` builds a bare
`httpx.Request` (no cookie merge,... (continued)

72 of 76 new or added lines in 6 files covered. (94.74%)

9187 of 9323 relevant lines covered (98.54%)

0.99 hits per line

Uncovered Changes

Lines Coverage ∆ File
4
97.14
-0.58% src/axiam_sdk/_client.py
Jobs
ID Job ID Ran Files Coverage
1 34778531440.1 13 Sep 2026 07:44PM UTC 78
98.54
GitHub Action Run
Source Files on build 34778531440
  • Tree
  • List 78
  • Changed 6
  • Source Changed 6
  • Coverage Changed 6
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #34778531440
  • 2383e350 on github
  • Prev Build on main (#34756454021)
  • Next Build on main (#34931999901)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc