• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

stacklok / toolhive / 36266379326
71%

Build:
DEFAULT BRANCH: main
Ran 26 Sep 2026 07:38PM UTC
Jobs 1
Files 939
Run time 2min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

26 Sep 2026 07:31PM UTC coverage: 70.888% (+0.02%) from 70.867%
36266379326

push

github

web-flow
Merge commit from fork

* Bind OAuth callback to the initiating browser

The embedded authorization server loaded a pending authorization at
/oauth/callback purely by the upstream state parameter. Nothing tied the
record to the browser that called /oauth/authorize, so an attacker could
start a flow for their own client, hand the upstream IdP URL to a victim,
and receive an authorization code minted for the victim's identity
(GHSA-2gjv-f568-6cxp).

/oauth/authorize now sets a per-flow, HttpOnly, SameSite=Lax cookie whose
SHA-256 is stored on the pending record, and the callback completes a leg
only when the calling browser presents a matching cookie. The cookie uses
the __Host- prefix whenever the browser-facing authorize URL is https so
a sibling subdomain cannot plant a matching value. Each multi-upstream
chain leg mints its own binding. A callback without a valid binding is
answered with a plain 400 and consumes the record; it is never redirected
to the client's redirect URI. Records without a binding hash are refused
by storage and rejected at the callback. Config validation warns at
startup when an upstream's redirect_uri host differs from the authorize
host, since a host-only cookie cannot bridge them.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* Bind device-flow login to the submitting browser

The device flow's verification page shares /oauth/callback with the
authorization-code flow and had the same gap: POST /oauth/device stored a
PendingDeviceLogin keyed only by the upstream state, so whoever reached the
callback with that state completed the login. A user_code holder could hand
the upstream URL to someone else and have that person's identity land on the
confirmation page for the holder's device (RFC 8628 Section 5.4).

The submit handler now mints the same browser-binding cookie and stores its
hash on the PendingDeviceLogin. Both the completion path and the
upstream-error path require the cookie; a foreign browser gets 400, ... (continued)

185 of 201 new or added lines in 10 files covered. (92.04%)

22 existing lines in 5 files now uncovered.

84545 of 119266 relevant lines covered (70.89%)

108.28 hits per line

Uncovered Changes

Lines Coverage ∆ File
6
69.35
-0.46% test/integration/authserver/helpers/http_client.go
4
91.38
-0.19% pkg/authserver/config.go
4
94.94
pkg/authserver/server/handlers/browser_binding.go
2
66.39
2.68% pkg/authserver/server/handlers/device_verification.go

Coverage Regressions

Lines Coverage ∆ File
6
19.87
-3.97% pkg/client/manager.go
6
72.34
-6.38% pkg/secrets/keyring/keyctl_linux.go
6
59.0
-0.62% pkg/workloads/manager.go
3
61.43
-4.29% pkg/state/runconfig.go
1
80.39
0.0% pkg/authserver/server/handlers/device_verification_render.go
Jobs
ID Job ID Ran Files Coverage
1 36266379326.1 26 Sep 2026 07:38PM UTC 939
70.89
GitHub Action Run
Source Files on build 36266379326
  • Tree
  • List 939
  • Changed 18
  • Source Changed 12
  • Coverage Changed 18
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #36266379326
  • 024c042f on github
  • Prev Build on main (#36155513199)
  • Next Build on main (#36269948559)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc