• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

SeaweedbrainCY / zero-totp / 26850636017 / 1
92%
main: 92%

Build:
Build:
LAST BUILD BRANCH: dependabot/pip/api/starlette-1.0.1
DEFAULT BRANCH: main
Ran 02 Jun 2026 10:02PM UTC
Files 266
Run time 10s
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

02 Jun 2026 10:01PM UTC coverage: 61.546% (-0.04%) from 61.583%
26850636017.1

push

github

SeaweedbrainCY
feat(api): If the detected Origin is likely a mobile app, tokens are also returned in the body

The Origin header is used to know if the origin app is capacitor or not. This header is spoofable, but only on a hijacked browser. Innocent user cannot have this modified without a compromised browser.
Attacker can spoof their own Origin header. In that case there is no sensitive information that isn't already transmitted in the SetCookies header.

It's more a precaution feature than a security feature

13609 of 22112 relevant lines covered (61.55%)

0.62 hits per line

Source Files on job 26850636017.1
  • Tree
  • List 266
  • Changed 81
  • Source Changed 3
  • Coverage Changed 81
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Build 26850636017
  • 440742d4 on github
  • Prev Job for on feat/add_ios_app (#26847366813.1)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc