• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

ilpanich / axiam-c-sdk / 34778558808
92%

Build:
DEFAULT BRANCH: main
Ran 13 Sep 2026 07:46PM UTC
Jobs 1
Files 31
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

13 Sep 2026 07:43PM UTC coverage: 92.388% (-0.06%) from 92.45%
34778558808

push

github

web-flow
feat(webauthn,pki): sign_csr and forced-setup passkey enrolment (F-1, contract 1.45) (#60)

Re-vendors CONTRACT.md, openapi.json and management-registry.json from
ilpanich/axiam@3d5b279 (contract 1.45) and implements this repo's share of
F-1: C-1's certificates.sign_csr and M-3's WebAuthn setup pair. No proto/
directory exists in this repo and none is added.

C-1 (mechanical). scripts/gen_management.py --check confirmed the vendored
registry already carries certificates.sign_csr -> POST
/api/v1/certificates/sign-csr, and running the generator produced
axiam_certificates_sign_csr(), the SignCertificateCsrRequest model
(axiam_mgmt_sign_certificate_csr_request_t) and its generated route/model
round-trip tests entirely on its own -- no hand-written model was needed.
The response type is the existing axiam_mgmt_certificate_t, not the
generated one with a mandatory private_key_pem: there is no key to return
for a CSR-signed certificate. Two hand-written tests in
test_management_semantics.c pin this at both layers -- the operation's
signature (compile-time: the wrong return type would not build) and the
model itself (a parse+build round trip proves Certificate has no slot to
carry a private key through even if a server sent one by mistake). The
management surface's operation count moved 159 -> 160 across 24 namespaces,
exactly as the axiam-side EXECUTED block predicted; the generated surface
test now asserts 160.

M-3 (mirror). axiam_webauthn_setup_register_start() and
axiam_webauthn_setup_register_finish() are the WebAuthn twin of
axiam_mfa_setup_enroll()/axiam_mfa_setup_confirm(): reached from the same
setup_token a login's mfa_setup_required interruption returns, so a user of
an MFA-enforcing tenant is no longer required to own a TOTP app to finish
signing in. Neither call takes a session or calls require_session() -- the
setup token is the only credential, and travels in the body exactly as
mfa_setup_enroll/confirm's does. finish adopts credentials exact... (continued)

10678 of 12606 branches covered (84.71%)

Branch coverage included in aggregate %.

128 of 144 new or added lines in 3 files covered. (88.89%)

16302 of 16597 relevant lines covered (98.22%)

946.18 hits per line

Uncovered Changes

Lines Coverage ∆ File
16
86.34
-4.09% src/webauthn.c
Jobs
ID Job ID Ran Files Coverage
1 34778558808.1 13 Sep 2026 07:46PM UTC 31
92.39
GitHub Action Run
Source Files on build 34778558808
  • Tree
  • List 31
  • Changed 9
  • Source Changed 3
  • Coverage Changed 9
Coverage ∆ File Lines Relevant Covered Missed Hits/Line Branch Hits Branch Misses
  • Back to Repo
  • Github Actions Build #34778558808
  • c13e4017 on github
  • Prev Build on main (#34756502124)
  • Next Build on main (#34931832857)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc