• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

archetech / archon / 36477011198
87%

Build:
DEFAULT BRANCH: main
Ran 28 Sep 2026 08:13PM UTC
Jobs 1
Files 3
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

28 Sep 2026 08:07PM UTC coverage: 86.667%. Remained the same
36477011198

push

github

web-flow
fix(keymaster): make Python challenge responses interoperable with TypeScript (#1301)

* fix(keymaster): make Python challenge responses interoperable with TypeScript

Python create_response now presents each credential through its own
presentation DID carrying the credential's cipher_hash, and
verify_response applies the TypeScript checks: live credential and
presentation, matching hashes, a valid issuer proof, and the challenge's
schema and issuer list. Entries that embed the credential instead of
naming a presentation DID are not counted in either port.

Cross-port fixtures, generated by running both keymasters against one
Gatekeeper, let each unit suite verify the other port's responses.

Closes #1300

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(keymaster): bind verified credentials to their issuer, asset and request

Response verification in both ports now counts a presented credential
only when both envelopes carry equal cipher hashes, the credential has a
valid proof by its declared issuer, it lives at the presented DID (its
signed id, or issuer control of the asset for credentials without one),
and it names a schema an unsatisfied challenge request accepts. Each
request is satisfied once, each credential DID counts once, and match
means every request is satisfied.

Each case was reachable with real signed operations before this change:
a holder could self-sign a credential naming a trusted issuer, copy a
revoked credential to a new asset, present a schema-less or unhashed
credential, or repeat one credential to satisfy several requests.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(keymaster): pair challenge requests and credentials by maximum matching

Holders chose each request's credential independently or first-fit, so
TypeScript presented one credential for repeated requests, which the
verifier now counts once, and both ports could spend a credential on a
broad request that a narrower one needed. Verif... (continued)

66 of 76 branches covered (86.84%)

Branch coverage included in aggregate %.

12 of 14 relevant lines covered (85.71%)

12.57 hits per line

Jobs
ID Job ID Ran Files Coverage
1 36477011198.1 28 Sep 2026 08:13PM UTC 3
86.67
GitHub Action Run
Source Files on build 36477011198
  • Tree
  • List 3
  • Changed 0
  • Source Changed 0
  • Coverage Changed 0
Coverage ∆ File Lines Relevant Covered Missed Hits/Line Branch Hits Branch Misses
  • Back to Repo
  • Github Actions Build #36477011198
  • 1fd01daa on github
  • Prev Build on main (#36468173206)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc