• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

ilpanich / axiam-go-sdk / 34778552691
95%

Build:
DEFAULT BRANCH: main
Ran 13 Sep 2026 07:46PM UTC
Jobs 1
Files 85
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

13 Sep 2026 07:43PM UTC coverage: 94.447% (-0.03%) from 94.474%
34778552691

push

github

web-flow
Contract 1.45: setup-token passkey enrolment and CSR-signed certificates (#78)

* feat(auth,certificates): sign-CSR certificates and passkey first-factor setup (F-1)

Fan-out of AXIAM's mfa-first-login-and-csr-issuance-plan.md items C-1 and
M-3, re-vendoring contract 1.45 from ilpanich/axiam@3d5b279.

C-1 — certificates.sign_csr (mechanical). Ran
internal/cmd/genmanagement against the re-vendored management-registry.json
and openapi.json: it emitted Certificates().SignCSR, the
SignCertificateCSRRequest model, and updated the generated surface test's
operation count (159 -> 160) on its own — nothing here was hand-written.
Its response type is the plain Certificate, not GeneratedCertificate,
because AXIAM never sees the caller's key; a new hand-written test
(TestManagement_SignCSRReturnsNoPrivateKeyField) pins that structurally,
by reflecting over Certificate's fields, rather than by checking an empty
string a server could still satisfy.

M-3 — WebauthnSetupRegisterStart / WebauthnSetupRegisterFinish (mirror,
with one real design problem). These are the setup-token twins of
WebauthnRegisterStart/Finish, reached exactly like MfaSetupEnroll /
MfaSetupConfirm when Login answers MFASetupRequired. CONTRACT.md §24.1 is
explicit that the pair takes no session and that an SDK "MUST NOT attach
its session credential" to either call, however the client is otherwise
configured.

That turned out not to be free in this SDK: net/http.Client attaches
every cookie-jar cookie matching the request URL unconditionally whenever
a Jar is set, with no per-request opt-out and no way to suppress it by
setting a Cookie header manually (the jar's cookies are appended on top,
not skipped). Reaching the requirement needed a real mechanism, not just
skipping a helper call:

  - sessionlessWebauthnPost bypasses doRequest/decorateRequest (the choke
    point that echoes a captured CSRF token and attaches an adopted
    LoginClientCredentials bearer token) and sends through a throwawa... (continued)

93 of 101 new or added lines in 2 files covered. (92.08%)

8334 of 8824 relevant lines covered (94.45%)

267.41 hits per line

Uncovered Changes

Lines Coverage ∆ File
8
91.72
-0.32% webauthn.go
Jobs
ID Job ID Ran Files Coverage
1 34778552691.1 13 Sep 2026 07:46PM UTC 85
94.45
GitHub Action Run
Source Files on build 34778552691
  • Tree
  • List 85
  • Changed 3
  • Source Changed 3
  • Coverage Changed 3
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #34778552691
  • b9e99d8f on github
  • Prev Build on main (#34756477845)
  • Next Build on main (#34887077904)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc