• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

hyperledger / fabric-x-committer / 37207432836
90%
main: 91%

Build:
Build:
LAST BUILD BRANCH: feature/adding_release_binary_workflow
DEFAULT BRANCH: main
Ran 04 Oct 2026 02:01PM UTC
Jobs 6
Files 148
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

04 Oct 2026 01:00PM UTC coverage: 90.282%. First build
37207432836

Pull #848

github

dean-amar
[auth] Add the Auth Service: nonce challenge, certificate-bound tokens, and authorization

#### Type of change

- New feature

#### Description

- New `auth` service (`committer start auth`) with three RPCs: `IssueNonce` hands out a single-use
  challenge, `Authenticate` exchanges an envelope signed over it for an opaque token bound to the
  client's TLS certificate, and `Authorize` checks a token against a resource's policy.
- Tokens (stored by hash) and nonces live in two new state-database tables, `auth_tokens` and
  `auth_nonces`, created by `init-db`, so any instance serves any request.
- Policy comes from the committed channel configuration's `ACLs` section, defaulting to
  `/Channel/Application/Readers`, and is re-read as the configuration changes.
- `statedb.ReadConfigTransaction` is the shared reader of the committed configuration (auth and query).
- Client helpers in `utils/acl`: `IssueToken`, `BuildAuthEnvelope`, `TLSCertHash`.
- Adds `grpcerror.WrapUnavailable`, `WrapUnauthenticated` and `WrapPermissionDenied`.

#### Additional details (Optional)

- Nothing enforces tokens yet; the Query Service and Sidecar are wired in #845.
- Temporarily requires the `fabric-x-common` fork in `go.mod` (envelope helper, `auth` test peer,
  `configtx.yaml` ACLs); the `replace` is removed once those changes are released upstream.

#### Related issues

- resolves #844
- related to #592

Signed-off-by: Dean Amar <Dean.Amar@ibm.com>
Pull Request #848: [ACL] Add the Auth Service: nonce challenge, certificate-bound tokens, and authorization [1/4]

338 of 441 new or added lines in 15 files covered. (76.64%)

10108 of 11196 relevant lines covered (90.28%)

40740.38 hits per line

Uncovered Changes

Lines Coverage ∆ File
54
75.0
service/auth/auth_service.go
22
69.01
service/auth/database.go
8
81.4
service/auth/config_provider.go
8
77.14
utils/acl/issue.go
7
72.0
service/auth/policy.go
2
84.09
cmd/committer/start_cmd.go
2
83.33
utils/statedb/config_transaction.go
Jobs
ID Job ID Ran Files Coverage
1 db-test - 37207432836.1 04 Oct 2026 02:01PM UTC 148
78.38
GitHub Action Run
2 unit-test - 37207432836.2 04 Oct 2026 02:02PM UTC 96
85.76
GitHub Action Run
3 core-db-test - 37207432836.3 04 Oct 2026 02:04PM UTC 115
50.34
GitHub Action Run
4 db-test - 37207432836.4 04 Oct 2026 03:48PM UTC 148
78.47
GitHub Action Run
5 db-test - 37207432836.5 04 Oct 2026 03:53PM UTC 148
78.18
GitHub Action Run
6 db-test - 37207432836.6 04 Oct 2026 04:01PM UTC 148
78.18
GitHub Action Run
Source Files on build 37207432836
  • Tree
  • List 148
  • Changed 0
  • Source Changed 0
  • Coverage Changed 0
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Pull Request #848
  • PR Base - main (#36705432257)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc