Skip to content

Harden ACME storage and expand security coverage - #155

Merged
matveynator merged 2 commits into
mainfrom
security-tests/database-domain-isolation
Sep 27, 2026
Merged

matveynator merged 2 commits into
mainfrom
security-tests/database-domain-isolation

Conversation

@matveynator

Copy link
Copy Markdown
Owner

Summary

  • reject unsafe ACME domains before they can escape the certificate cache directory
  • add meaningful fail-closed tests for ACME, account authentication, and cross-compilation orchestration
  • cover SQL trigger failures, replay/expiry boundaries, malformed protocol responses, and missing build infrastructure

Validation

  • accountauth: 90.3% statement coverage
  • channelacme: 85.4% statement coverage
  • crosscompile: 83.7% statement coverage
  • targeted sitebrush security tests pass
  • full pkg/scripts run is blocked by an existing database test that binds IPv6 localhost, which this sandbox forbids

The remaining two requested package thresholds are not honestly above 90% yet; the uncovered code is primarily OS/standard-library failure paths and platform-specific Docker/macOS orchestration.

@codecov-commenter

Copy link
Copy Markdown

⚠️ Please install the 'codecov app svg image' to ensure uploads and comments are reliably processed by Codecov.

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@matveynator
matveynator merged commit ef4d45b into main Sep 27, 2026
7 checks passed
@matveynator
matveynator deleted the security-tests/database-domain-isolation branch September 27, 2026 05:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants