• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

ilpanich / axiam-swift-sdk / 34778554828
95%

Build:
DEFAULT BRANCH: main
Ran 13 Sep 2026 07:51PM UTC
Jobs 1
Files 50
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

13 Sep 2026 07:43PM UTC coverage: 94.903% (+0.04%) from 94.862%
34778554828

push

github

web-flow
feat(webauthn,certificates): setup-token passkey enrolment and CSR-signed certificates (contract 1.45) (#61)

F-1 fan-out for the mfa-first-login-and-csr-issuance-plan's M-3 and C-1,
re-vendoring CONTRACT.md/openapi.json/management-registry.json/proto/ from
ilpanich/axiam@3d5b279 (contract 1.45).

**C-1, mechanical.** `Scripts/gen_management.py` picked up
`certificates.sign_csr` -> `POST /api/v1/certificates/sign-csr` from the
vendored registry and generated `signCSR(body:) -> Certificate` plus the
`SignCertificateCsrRequest` model itself (the generator already emits request
models from openapi.json, so no hand-written type was needed). The response
is the existing `Certificate`, never `GeneratedCertificate` — its
`privateKeyPEM` is mandatory and would always be absent here. The generated
conformance suite's own operation-count assertion moved 159 -> 160 as part of
the regeneration; no test needed hunting down by hand. Added a hand-written
model round-trip test asserting the decoded `Certificate` `signCSR` returns
carries no private-key field at all (via `Mirror`, not a type-level assertion
that a refactor could silently point at the wrong model), contrasted against
a `GeneratedCertificate` decode that legitimately does carry one.

**M-3, the mirror.** `webauthnSetupRegisterStart`/`webauthnSetupRegisterFinish`
beside the existing `webauthnRegisterStart`/`Finish`, wired to the new
`POST /api/v1/auth/webauthn/setup/register/{start,finish}`. Per CONTRACT.md
§24.1/§24.8 these take no session at all — the setup token in the body is the
only credential — so they route through a new `AxiamClient.setupTokenRawSend`
transport rather than the existing `webauthnRawSend`: it still emits the §5
tenant header and still captures a `Set-Cookie`/`X-CSRF-Token` the response
sets (so `setupRegisterFinish` can complete the interrupted login), but never
attaches this client's own session cookie, even when one happens to be
configured. `webauthnRawSend`/`rawSend` always re... (continued)

94 of 94 new or added lines in 4 files covered. (100.0%)

10892 of 11477 relevant lines covered (94.9%)

11600984.49 hits per line

Jobs
ID Job ID Ran Files Coverage
1 34778554828.1 13 Sep 2026 07:51PM UTC 50
94.9
GitHub Action Run
Source Files on build 34778554828
  • Tree
  • List 50
  • Changed 5
  • Source Changed 5
  • Coverage Changed 5
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #34778554828
  • 39e3d9cb on github
  • Prev Build on main (#34756495536)
  • Next Build on main (#34931749406)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc