• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

ilpanich / axiam-rust-sdk / 34778564413
94%

Build:
DEFAULT BRANCH: main
Ran 13 Sep 2026 07:51PM UTC
Jobs 1
Files 79
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

13 Sep 2026 07:43PM UTC coverage: 93.07% (-0.08%) from 93.151%
34778564413

push

github

web-flow
feat(pki,webauthn): certificates.sign_csr and the passkey setup pair (contract 1.45) (#105)

* feat: certificates.sign_csr and the webauthn setup pair (contract 1.45)

Re-vendors CONTRACT.md, openapi.json, management-registry.json and proto/
from axiam at 3d5b279 (contract 1.45) and implements this SDK's share of
the two additive operations it introduces.

C-1, the mechanical half: `certificates.sign_csr` — a certificate for a
key AXIAM never sees. `tools/gen_management.py` regenerates the §27
surface from the re-vendored registry; the management surface moves
159 -> 160 operations across the same 24 namespaces. The generator
already emits `SignCertificateCsrRequest`, so nothing needed
hand-writing, and it wired the operation's response to the existing
`Certificate` — never `GeneratedCertificate`, whose `private_key_pem`
field is mandatory and would always be absent here (§27.5). Two tests
in `management_semantics_test.rs` pin that: one constructs every field
of `Certificate` and asserts the serialized form carries nothing that
reads as a private key, the other round-trips `sign_csr` against a
fixture that sends a `private_key_pem` anyway and confirms it cannot
resurface on the decoded value.

M-3, the mirror: `webauthn_setup_register_start` /
`webauthn_setup_register_finish` in `src/rest/webauthn.rs`, beside the
six existing operations. The WebAuthn twin of `mfa_setup_enroll` /
`mfa_setup_confirm` — a user of a tenant that requires MFA is no longer
limited to TOTP for the first factor a forced login enrolment demands.

Both take no session at all, and neither attaches this client's own
session credential even when one is configured (§24.1): a dedicated
`webauthn_post_no_session` helper skips the `X-CSRF-Token` forwarding
every other call in this module does, and pre-empts `reqwest`'s cookie
jar with an explicit empty `Cookie` header — the jar only auto-populates
one when the outgoing request does not already carry one, so this is
enough to keep a con... (continued)

71 of 88 new or added lines in 2 files covered. (80.68%)

12570 of 13506 relevant lines covered (93.07%)

27.6 hits per line

Uncovered Changes

Lines Coverage ∆ File
17
89.46
-4.24% src/rest/webauthn.rs
Jobs
ID Job ID Ran Files Coverage
1 34778564413.1 13 Sep 2026 07:51PM UTC 79
93.07
GitHub Action Run
Source Files on build 34778564413
  • Tree
  • List 79
  • Changed 3
  • Source Changed 3
  • Coverage Changed 3
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #34778564413
  • cb31e40d on github
  • Prev Build on main (#34756439379)
  • Next Build on main (#34901310123)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc