• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

Rotorsoft / act-root / 36873639210
100%

Build:
DEFAULT BRANCH: master
Ran 01 Oct 2026 02:08PM UTC
Jobs 1
Files 118
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

01 Oct 2026 02:05PM UTC coverage: 100.0%. Remained the same
36873639210

push

github

web-flow
feat(act): let a read decline the pii payload, so a corrupt row strands nothing (#1675) (#1715)

* feat(act): let a read decline the pii payload, so a corrupt row strands nothing

Sensitive fields are decrypted by the adapter as it materializes each row.
One unreadable payload therefore failed the ENTIRE read, and the correlate
scan is one of those reads — it resolves reaction targets from name and
stream and throws the payload away. Since correlate is the sole producer of
the work mark, a single corrupt row stopped every stream's reactions,
permanently: nothing blocked, blocked_streams() empty, and nothing naming
the row. app.audit(), the tool for finding corrupt data, died the same way
on the first bad row.

Query.with_pii defaults to true and reproduces prior behavior exactly. Set
false and the store returns pii: null without ever decrypting, so a read
that does not want the payload cannot fail on it. null rather than the
stored ciphertext is load-bearing — pii_gate treats any non-null pii as
discloseable and would merge base64 into data.

Correlate now declines it. A dynamic .to(event => ...) resolver therefore
sees pii: null; that is deliberate and is itself a fix, since correlate runs
actor-less and feeding a resolver decrypted plaintext is the un-gated
disclosure #1673 corrected on the drain return.

The audit locates a bad row by itself: when its scan trips it re-reads the
single next row declining the payload, which cannot fail on the same cause
and returns that row's stream and id. So no adapter carries decryption error
handling — the earlier attempt at that shape is withdrawn in #1696.

RFC 1675 covers the new field and the rejected alternatives.

Closes #1675

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix(act): contain a failed fetch per stream so one bad row stalls one stream

The drain's reads were already per stream but shared one Promise.all, so one
stream's read failure rejected the whole cycle and every he... (continued)

4382 of 4382 branches covered (100.0%)

Branch coverage included in aggregate %.

75 of 75 new or added lines in 7 files covered. (100.0%)

9492 of 9492 relevant lines covered (100.0%)

1227.92 hits per line

Jobs
ID Job ID Ran Files Coverage
1 36873639210.1 01 Oct 2026 02:08PM UTC 118
100.0
GitHub Action Run
Source Files on build 36873639210
  • Tree
  • List 118
  • Changed 9
  • Source Changed 9
  • Coverage Changed 8
Coverage ∆ File Lines Relevant Covered Missed Hits/Line Branch Hits Branch Misses
  • Back to Repo
  • Github Actions Build #36873639210
  • 5c5550f3 on github
  • Prev Build on master (#36867269979)
  • Next Build on master (#36907262934)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc