• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

stacklok / toolhive / 34892792280
71%

Build:
DEFAULT BRANCH: main
Ran 14 Sep 2026 08:33PM UTC
Jobs 1
Files 923
Run time 2min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

14 Sep 2026 08:25PM UTC coverage: 70.657% (+0.09%) from 70.567%
34892792280

push

github

web-flow
Document request-claim fallback provenance (#6656)

* Document request-claim fallback provenance

Cedar's request-token fallback paths were documented as if only delegated
and JWT-bearer tokens could reach them. The opaque-access-token path was
missing from the operator guide entirely, even though Google and GitHub
upstreams always take it, and the multi-upstream caveat that fallback
profile claims belong to the first upstream in the chain was recorded only
under delegation although it applies to both fallback paths equally.

"Primary upstream" also meant two different things across the codebase:
first in the chain, and the provider Cedar trusts for claims. They
coincide by default, so the collision was easy to miss and load-bearing
for authorization when pinning explicitly.

Comments and documentation only; no behavior change. The claim-resolution
gap these docs describe is tracked separately in #6655.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Correct fallback claim origins per grant type

The first draft claimed both request-token fallback labels mirror name and
email from the first upstream in the chain. That is true only on the
opaque-token path. RFC 7523 JWT-bearer tokens carry neither claim, and RFC
8693 delegated tokens copy them from the subject token, which holds an
external IdP's own assertion when that token came from a trusted external
issuer. The draft also contradicted correct existing text in the same file.

Split the explanation by grant instead, and drop the paragraph naming the
two senses of "primary upstream": after this branch renames the chain-state
comments, no first-in-chain sense remains for it to disambiguate.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Note the opaque-token fallback on the Cedar option

ConfigOptions.PrimaryUpstreamProvider described the session-less nil map as
the sole case where request-token claims are evaluated. The opaque-token
path does the same th... (continued)

81422 of 115235 relevant lines covered (70.66%)

97.33 hits per line

Coverage Regressions

Lines Coverage ∆ File
63
9.03
9.03% pkg/tui/update.go
53
4.74
4.74% pkg/tui/view.go
45
59.63
-4.68% pkg/workloads/manager.go
40
28.57
0.15% pkg/secrets/factory.go
34
80.1
7.66% pkg/secrets/encrypted.go
21
12.31
12.31% pkg/telemetry/serve.go
18
56.55
34.48% pkg/tui/update_search.go
13
16.83
0.0% cmd/thv/app/server.go
12
0.0
0.0% cmd/thv/app/ui/spinner.go
11
90.18
-2.55% pkg/sentry/sentry.go
10
0.0
0.0% cmd/thv/app/tui.go
7
79.22
1.14% pkg/telemetry/config.go
3
82.77
-0.23% pkg/authserver/storage/redis.go
3
0.0
-100.0% pkg/workloads/sysproc_unix.go
2
68.8
-0.85% pkg/ignore/processor.go
1
94.86
0.0% pkg/authserver/storage/memory.go
Jobs
ID Job ID Ran Files Coverage
1 34892792280.1 14 Sep 2026 08:33PM UTC 923
70.66
GitHub Action Run
Source Files on build 34892792280
  • Tree
  • List 923
  • Changed 44
  • Source Changed 36
  • Coverage Changed 27
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #34892792280
  • c2621068 on github
  • Prev Build on main (#34885265325)
  • Next Build on main (#34940567076)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc