• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

decentraland / social-service-ea / 36774376308
91%
main: 91%

Build:
Build:
LAST BUILD BRANCH: 1.13.12
DEFAULT BRANCH: main
Ran 30 Sep 2026 08:47PM UTC
Jobs 1
Files 210
Run time 2min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

30 Sep 2026 08:40PM UTC coverage: 91.222% (+0.02%) from 91.207%
36774376308

push

github

web-flow
fix: treat a malformed websocket auth frame as a client rejection (#501)

* fix: treat a malformed websocket auth frame as a client rejection

Sentry: https://decentraland.sentry.io/issues/7713056598/ (SOCIAL-SERVICE-EA-3H)
Exception: SyntaxError (JSON.parse), culprit authenticateUser (controllers.handlers.uws:ws-handler)

authenticateUser passed the client's first frame straight to JSON.parse. A frame that is not
JSON raised a SyntaxError, which isExpectedAuthRejection cannot classify (it only knows the
middleware's 4xx RequestError). So every such frame was logged at error, sent to Sentry and
counted as a server_error. That is 32 events so far from 1.13.9 and 1.13.10. A JSON null
frame took a similar path: verify() threw a TypeError on it.

#473 kept this path reporting only because the error "never reached the middleware". The
fault is still the client's, the same as a malformed auth chain, which the middleware rejects
with a 400. parseAuthChainHeaders now raises that same 400 RequestError, with a fixed message
that never echoes the frame, when the frame is not JSON or not an object. It then leaves through
the existing path: warn, no Sentry, ws_auth_errors{type="client_rejected"}, 3003 close.

Catalyst 503s and unexpected throws inside verify() keep reporting.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix: reject non-string auth header values in the websocket auth frame

Review follow-up for SOCIAL-SERVICE-EA-3H (https://decentraland.sentry.io/issues/7713056598/).
It also covers SOCIAL-SERVICE-EA-3J (https://decentraland.sentry.io/issues/7713296423/).

An x-identity-timestamp sent as a JSON number passes the middleware's timestamp and expiry
checks, then crashes createPayload with "TypeError: firstOf(...)?.toLowerCase is not a
function" (3J). That throw is reported as a server error from a frame the client built.
parseAuthChainHeaders now rejects, with the same 400, any x-identity-* header whose value is
not a string or an array o... (continued)

2614 of 3015 branches covered (86.7%)

Branch coverage included in aggregate %.

14 of 14 new or added lines in 1 file covered. (100.0%)

6261 of 6714 relevant lines covered (93.25%)

93.77 hits per line

Jobs
ID Job ID Ran Files Coverage
1 36774376308.1 30 Sep 2026 08:47PM UTC 420
92.09
GitHub Action Run
Source Files on build 36774376308
  • Tree
  • List 210
  • Changed 164
  • Source Changed 3
  • Coverage Changed 164
Coverage ∆ File Lines Relevant Covered Missed Hits/Line Branch Hits Branch Misses
  • Back to Repo
  • Github Actions Build #36774376308
  • 02f40ff2 on github
  • Prev Build on 1.13.10 (#35004170927)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc