• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

hyperscale-stack / security / 38014578498
94%
master: 95%

Build:
Build:
LAST BUILD BRANCH: feature/94-oauth2-empty-client-secret
DEFAULT BRANCH: master
Ran 10 Oct 2026 01:49AM UTC
Jobs 1
Files 94
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

10 Oct 2026 01:45AM UTC coverage: 94.398% (+2.4%) from 92.032%
38014578498

Pull #91

github

euskadi31
docs(oauth2): require token-family state to outlive its retention

The token-family documentation claimed more than the stores guarantee.
A lookup does treat a token whose family state is lost as revoked, but
the next issuance into that family records it active again: losing a
revoked family's state before its retention ends — an evicted Redis key,
a family row deleted early — can revive its tokens. The Redis package
documentation called eviction harmless and noeviction a recommendation,
and the SQL one called an early family delete safe.

Keeping that state for its whole retention is now a stated requirement:
the Storage godoc (I8), the SQL cleanup rules (never delete a family
row before its expires_at), the Redis requirements (maxmemory-policy
noeviction, since family keys carry TTLs and volatile-* policies evict
them too), the security considerations, the migration guide and the
changelog, which also names the Redis 6.0 requirement KEEPTTL brings.
I6 now mentions the invalid_request for a malformed family ID, the
READ COMMITTED pin is scoped to the token-family transactions it
applies to, and only the token-family Redis scripts are claimed safe to
resend. Refs #82.
Pull Request #91: fix(oauth2): make refresh-family revocation reliable across stores

1002 of 1029 new or added lines in 16 files covered. (97.38%)

2 existing lines in 2 files now uncovered.

4634 of 4909 relevant lines covered (94.4%)

21.32 hits per line

Uncovered Changes

Lines Coverage ∆ File
8
91.79
6.79% oauth2/store/redis/store.go
8
95.82
12.34% oauth2/storetest/conformance.go
7
93.88
4.58% oauth2/store/sql/store.go
4
98.84
oauth2/storetest/family.go

Coverage Regressions

Lines Coverage ∆ File
1
91.79
6.79% oauth2/store/redis/store.go
1
93.88
4.58% oauth2/store/sql/store.go
Jobs
ID Job ID Ran Files Coverage
1 38014578498.1 10 Oct 2026 01:49AM UTC 94
94.4
GitHub Action Run
Source Files on build 38014578498
  • Tree
  • List 94
  • Changed 17
  • Source Changed 0
  • Coverage Changed 17
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Pull Request #91
  • PR Base - master (#38008716408)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc