• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

ilpanich / axiam-cplusplus-sdk / 34778560658
95%

Build:
DEFAULT BRANCH: main
Ran 13 Sep 2026 07:45PM UTC
Jobs 1
Files 33
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

13 Sep 2026 07:43PM UTC coverage: 94.993% (-0.2%) from 95.227%
34778560658

push

github

web-flow
feat(pki,webauthn): sign-CSR certificates and passkey first-login setup (F-1) (#61)

Re-syncs this SDK against contract 1.45 and implements the two surfaces
it adds.

certificates().sign_csr() (§27) is generated from the re-vendored
registry like every other management operation: 159 -> 160 operations
across the same 24 namespaces. Its response is the existing Certificate
model, deliberately not GeneratedCertificate, whose private_key_pem is
mandatory and would always be absent here — the key stays with whoever
built the CSR and AXIAM never sees it.

webauthn_setup_register_start/finish (§24.1, §25.2 rule 2) are the
WebAuthn twin of mfa_setup_enroll/mfa_setup_confirm: same setup token as
their only credential, reached from the same LoginResult field, and
finish adopting a session exactly as mfa_setup_confirm does — decision
memo included, because it IS the completion of the login the tenant's
MFA policy interrupted.

§24.1's "no session credential on these two" is not free on a cookie-jar
transport. CurlTransport::perform_isolated() routes both calls onto a
fresh, unshared handle with no cookie engine, so a session cookie
already in the jar is never replayed; and because finish must still
ADOPT the session its own response sets, the Set-Cookie it receives is
merged back into the shared jar explicitly rather than relying on an
engine deliberately not there for the outgoing half. Both halves are
asserted against the real libcurl transport over a loopback socket, not
only against the in-memory fake — the fake has no jar to leak a session
out of in the first place.

Verified: ASan+UBSan and valgrind (--error-exitcode=9 --leak-check=full)
both clean over 1191 test cases / 3750 checks; plain Debug build green;
§27 drift-check, TLS-bypass gate and secret-scan gate all pass.


Claude-Session: https://claude.ai/code/session_01Kz53zeXGGKAjSNH81BZvX7

Co-authored-by: Claude <noreply@anthropic.com>

4944 of 5620 branches covered (87.97%)

Branch coverage included in aggregate %.

173 of 188 new or added lines in 4 files covered. (92.02%)

10328 of 10457 relevant lines covered (98.77%)

204.36 hits per line

Uncovered Changes

Lines Coverage ∆ File
15
87.57
-7.12% src/http_curl.cpp
Jobs
ID Job ID Ran Files Coverage
1 34778560658.1 13 Sep 2026 07:45PM UTC 33
94.99
GitHub Action Run
Source Files on build 34778560658
  • Tree
  • List 33
  • Changed 8
  • Source Changed 6
  • Coverage Changed 7
Coverage ∆ File Lines Relevant Covered Missed Hits/Line Branch Hits Branch Misses
  • Back to Repo
  • Github Actions Build #34778560658
  • 648c949b on github
  • Prev Build on main (#34756508211)
  • Next Build on main (#34931855047)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc