• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

FIWARE / VCVerifier / 36138807027
70%
main: 73%

Build:
Build:
LAST BUILD BRANCH: ticket-64/work
DEFAULT BRANCH: main
Ran 25 Sep 2026 01:06PM UTC
Jobs 1
Files 71
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

25 Sep 2026 01:05PM UTC coverage: 69.769% (+0.003%) from 69.766%
36138807027

Pull #128

github

Mortega5
fix(verifier): stop using the external client's state as the session key

The cross-device and same-device login flows reserved the session cache
entry under the state value supplied by the external OIDC client
(sessionCache.Add(state, ...), three call sites), and echoed that same
value back to the wallet as the OID4VP request's own state. Since go-cache's
Add fails if the key already exists, any client that resends the same state
across a retry (a page refresh, a double-submit, a back-button retry, or
simply a client that doesn't randomize state per attempt) got a hard
failure instead of being able to proceed.

Generate the verifier's own session id for every flow, and use it as the
sessionCache key, the wallet-facing OID4VP state, and the request_uri
lookup key. The external client's original state is now stored separately
on the session (loginSession.externalState) and is only ever echoed back to
that client at the very end, never used as a lookup key - so a repeated or
predictable external state can no longer collide with, or address, a
session it didn't create.

Response.SessionId is renamed to Response.ExternalState to make this
distinction explicit at the one place most likely to regress it: a
same-device or cross-device response must always echo the external state,
never the verifier's internal session id.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Pull Request #128: Stop using the external client's state as the session lookup key

18 of 31 new or added lines in 3 files covered. (58.06%)

7683 of 11012 relevant lines covered (69.77%)

0.8 hits per line

Uncovered Changes

Lines Coverage ∆ File
6
0.0
0.0% openapi/websocket.go
5
54.12
-0.25% openapi/api_api.go
2
66.46
0.19% verifier/verifier.go
Jobs
ID Job ID Ran Files Coverage
1 36138807027.1 25 Sep 2026 01:06PM UTC 71
69.77
GitHub Action Run
Source Files on build 36138807027
  • Tree
  • List 71
  • Changed 3
  • Source Changed 0
  • Coverage Changed 3
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Pull Request #128
  • PR Base - main (#35992326106)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc