• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

dunglas / mercure / 35754202441
90%
master: 93%

Build:
Build:
LAST BUILD BRANCH: main
DEFAULT BRANCH: master
Ran 22 Sep 2026 04:29PM UTC
Jobs 1
Files 34
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

22 Sep 2026 04:27PM UTC coverage: 88.641% (+0.3%) from 88.308%
35754202441

push

github

web-flow
Merge commit from fork

* fix: resolve reserved topics against the URL Pattern base

The guard resolved topics against a base whose path was the hub URL while
the matcher used one whose path was "/", so a path-relative topic landed
outside the reserved namespace for the guard and inside it for the matcher:
publishing ".well-known/mercure/subscriptions/exact/x/y" forged a frame onto
a subscriber's subscription-events pattern. The spec requires both to use the
hub's URL as the base.

(cherry picked from commit 24c859827)

* fix: refuse topics whose raw path is in the reserved namespace

The guard normalized dot segments away while the deprecated v8 matcher
compares raw strings, so publishing
"…/.well-known/mercure/subscriptions/../.." passed validation and still
matched a subscriber's reserved pattern.

(cherry picked from commit 28638e79f)

* perf: skip URL resolution for topics that cannot address the reserved namespace

Every publish resolved each of its topics against the hub URL through a full
WHATWG parse, at roughly 2.5 µs and 90 allocations per topic, only to find that
an ordinary topic lands nowhere near the reserved namespace.

An absolute URL with an authority is resolved without consulting the base, so
its path is spelled by its own bytes: one that does not spell the namespace's
last segment cannot reach it, and needs no resolution. Anything else, including
a reference that is empty or scheme-only once trimmed, can inherit the base
path and is still resolved.

* fix: resolve reserved topics against the base subscribers are matched with

Four crafted topics passed Update.Validate while matching a reserved
subscription pattern: "https:mercure/subscriptions/exact/x/y" against a hub
configured with an https resource identifier, " https:mercure/" with the leading
space the parser strips, a bare "https:", and
".../subscriptions/../../https://example.com", whose embedded scheme the
raw-p... (continued)

33 of 34 new or added lines in 2 files covered. (97.06%)

2263 of 2553 relevant lines covered (88.64%)

206.06 hits per line

Uncovered Changes

Lines Coverage ∆ File
1
98.44
3.7% reservedtopic.go
Jobs
ID Job ID Ran Files Coverage
1 0 - 35754202441.1 22 Sep 2026 04:29PM UTC 34
88.64
GitHub Action Run
Source Files on build 35754202441
  • Tree
  • List 34
  • Changed 4
  • Source Changed 0
  • Coverage Changed 4
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • 96a07f29 on github
  • Prev Build on main (#35753862129)
  • Next Build on main (#35758443469)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc