• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

wrouesnel / vouch / 37315189611
51%

Build:
DEFAULT BRANCH: main
Ran 05 Oct 2026 01:15PM UTC
Jobs 1
Files 20
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

05 Oct 2026 01:13PM UTC coverage: 51.131% (-0.6%) from 51.708%
37315189611

push

github

wrouesnel
Verify the password without leaving the account unlocked, and gate the unlock on a committed audit record

Security review changes to how the locked account is handled, plus a
durable, pluggable audit trail.

Account status and the password check:
- The target stays locked throughout. At the claim, vouch first confirms
  (via a bind) the account is genuinely locked and eligible, so claiming
  can't be used to unlock or lock an innocent account.
- It then briefly clears the lockout, binds as the user to check the
  password, and re-locks the account (directory.VerifyWhileLocked). AD
  forbids writing a non-zero lockoutTime, so the re-lock is done with
  failed binds up to the account's lockout threshold (read from the
  resultant PSO or the domain policy). Verified empirically on Samba.
- No password is kept between steps. A wrong password leaves the account
  locked; the user can retry. The permanent unlock happens only at
  confirm, so a wrong password can never leave an account unlocked.
- If the account can't be re-locked, it's disabled as a fail-safe and a
  relock_failed event is recorded.

Audit (pkg/audit):
- Pluggable sinks: file (fsync per line), SQL (pgx/mysql/sqlite, pure-Go,
  CGO-free), and HTTP including Splunk HEC with retries. Fan-out writes to
  all; a failure in any fails the write.
- The final unlock is gated: Confirm commits an unlock_authorized record
  and clears the lockout only if the sink commits it. If it can't, the
  unlock is refused (audit_failed) and the account stays locked.

Removes disableOnFailedVerification and the verification_failed outcome,
which no longer apply now that a wrong password never unlocks the account.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014EBFSg4NggxD8rZCRVtH1U

280 of 542 new or added lines in 12 files covered. (51.66%)

995 of 1946 relevant lines covered (51.13%)

7.68 hits per line

Uncovered Changes

Lines Coverage ∆ File
136
6.92
-4.66% pkg/directory/ldap.go
29
0.0
0.0% pkg/directory/directorytest/fake.go
21
66.13
pkg/audit/sql.go
18
76.32
pkg/audit/http.go
18
82.38
1.05% pkg/unlock/service.go
12
51.72
-2.12% pkg/entrypoints/vouch/command_run.go
11
65.63
pkg/audit/file.go
8
52.94
pkg/audit/multi.go
6
79.31
pkg/audit/config.go
2
0.0
pkg/audit/audit.go
1
0.0
0.0% pkg/api/api.gen.go
Jobs
ID Job ID Ran Files Coverage
1 37315189611.1 05 Oct 2026 01:15PM UTC 20
51.13
GitHub Action Run
Source Files on build 37315189611
  • Tree
  • List 20
  • Changed 9
  • Source Changed 0
  • Coverage Changed 9
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • 1b43ad09 on github
  • Prev Build on main (#37236656474)
  • Next Build on main (#37317919393)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc