• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

hyperscale-stack / security / 38008716408
95%

Build:
DEFAULT BRANCH: master
Ran 10 Oct 2026 12:22AM UTC
Jobs 1
Files 93
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

10 Oct 2026 12:21AM UTC coverage: 92.032% (+0.2%) from 91.812%
38008716408

push

github

web-flow
fix(oauth2): authorize token introspection callers

serveIntrospect authenticated its caller through the shared ClientAuth
chain, then threw the client away: any client the chain accepted could
introspect any token it held. A public client's client_id is no secret
— it ships inside every SPA and mobile app, and RFC 6749 §2.2 forbids
using it alone — yet it was enough to read the validity and claims of a
token, refresh tokens included: through the none method, or through
client_secret_basic / client_secret_post with the client's registered
secret (Basic: even an empty one), whether or not none was registered.
RFC 7662 §2.1 and §4 require the endpoint to authenticate the protected
resources calling it, and RFC 6749 §2.3 forbids relying on a public
client's authentication to identify it.

/introspect now answers only callers whose Type() is
ClientConfidential: a public client, whatever the method, and an
untyped client authenticated through Basic or Post (none already
refused it) get 401 invalid_client before the token is looked up.
/token and /revoke are unchanged, so a public client keeps running
authorization_code + PKCE, refreshing and revoking its own tokens with
none. The none method's description for a non-public client loses its
double quote, which the RFC 6749 §5.2 error_description charset
forbids.

The new ServerConfig.IntrospectionPolicy decides which active tokens
each caller may see, from the caller and an IntrospectedToken (kind,
client, subject, scope, audience, issuance and expiry — never the token
value): the specific authorization RFC 7662 §4 recommends, where
resource and tenant boundaries are enforced, refresh tokens included.
It only runs for active tokens. A denial answers a bare
{"active":false}, the same bytes as an unknown token (RFC 7662 §2.2); a
policy error fails closed the same way and reaches OnError as a
server_error, since a 500 would tell the caller the token is active.
Without a policy, any confidential client may intro... (continued)

65 of 65 new or added lines in 2 files covered. (100.0%)

3985 of 4330 relevant lines covered (92.03%)

14.32 hits per line

Jobs
ID Job ID Ran Files Coverage
1 38008716408.1 10 Oct 2026 12:22AM UTC 93
92.03
GitHub Action Run
Source Files on build 38008716408
  • Tree
  • List 93
  • Changed 3
  • Source Changed 0
  • Coverage Changed 3
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • c3b2963a on github
  • Prev Build on master (#38008266437)
  • Next Build on master (#38014756492)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc