Kanidm: A simple, secure, and fast identity management platform
This report presents the forensic synthetic code analysis of kanidm/kanidm, a Rust project with 5,127 GitHub stars. SynthScan v2.0 examined 434,858 lines of code across 1000 source files, recording 2459 pattern matches distributed across 16 syntactic categories. The overall adjusted score of 12.1 places this repository in the Low AI signal band.
The scanner applied 160+ deterministic lexical heuristics, multi-line block detectors, abstract syntax tree depth profilers, and a cross-file Jaccard similarity matrix to construct a statistically normalised synthetic code estimate. All matches are individually weighted by severity coefficient and contextual multiplier before summation, and the resulting headline score is temporally discounted to account for the repository's development history relative to the commercial emergence of large language model coding tooling (November 2022 onward).
Longitudinal tracking requires multiple scan runs. Once this repository is re-scanned after new commits land, this chart will visualise how the synthetic code signal evolves over time — enabling you to detect whether AI authorship is growing, stabilising, or being actively corrected by human engineers.
Classifies detected patterns by their diagnostic confidence and structural impact. CRITICAL patterns (coefficient 10) represent definitive synthetic signatures — hallucinated imports, explicit LLM attribution metadata — virtually never produced by human authors. HIGH (5) indicates strong structural tells such as cross-file repetition or cross-linguistic idioms. MEDIUM (2) covers recognisable conversational padding and AI-specific vocabulary. LOW (1) captures subtle indicators like tautological comments and generic boilerplate that require density to carry independent signal.
This horizontal bar chart decomposes the repository's raw synthetic code score by top-level directory, allowing you to pinpoint precisely which modules or components carry the highest AI authorship density. Directories with disproportionately high scores relative to their size warrant targeted manual review: concentrated AI signatures often trace back to mass-generated configuration layers, auto-ported test suites, LLM-scaffolded boilerplate classes, or entire subsystems authored under heavy copilot assistance. Use this view to prioritise your human code-review effort.
The scanner identified 2459 distinct pattern matches across 16 syntactic categories. Each entry below represents a discrete location in the source code where the engine recorded a statistically significant AI authorship indicator. Expand any category row to inspect the individual file paths, line numbers, code snippets, and the lexical context (CODE, COMMENT, or STRING) in which each match was detected.
Reading the findings table: The Severity column indicates the diagnostic confidence level (CRITICAL / HIGH / MEDIUM / LOW). The Context column identifies whether the match occurred inside executable code, an inline comment, or a string literal — comment-context matches receive a ×1.5 weight because LLMs systematically over-annotate. The ⚡ bolt icon marks clustered matches: three or more patterns within a 10-line window, each receiving an additional ×1.5 density multiplier as dense clusters constitute far stronger evidence of synthetic authorship than isolated hits.
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| HIGH | pykanidm/kanidm_openapi_client/configuration.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | pykanidm/kanidm_openapi_client/rest.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | pykanidm/kanidm_openapi_client/__init__.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | pykanidm/kanidm_openapi_client/exceptions.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | pykanidm/kanidm_openapi_client/api_client.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …/kanidm_openapi_client/models/single_string_request.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …kanidm/kanidm_openapi_client/models/scim_sort_order.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …kanidm_openapi_client/models/credential_detail_type.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | pykanidm/kanidm_openapi_client/models/filter_one_of1.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …openapi_client/models/identify_user_response_one_of.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …nidm_openapi_client/models/operation_error_one_of13.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …idm_openapi_client/models/consistency_error_one_of6.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | pykanidm/kanidm_openapi_client/models/auth_state.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …napi_client/models/scim_application_password_create.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …idm/kanidm_openapi_client/models/uat_purpose_status.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | pykanidm/kanidm_openapi_client/models/cu_reg_state.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | pykanidm/kanidm_openapi_client/models/uat_status.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …nidm/kanidm_openapi_client/models/scim_sync_request.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …dels/consistency_error_one_of16_keyprovidernotfound.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | pykanidm/kanidm_openapi_client/models/filter_one_of5.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …kanidm/kanidm_openapi_client/models/cu_intent_token.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | pykanidm/kanidm_openapi_client/models/ssh_public_key.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | pykanidm/kanidm_openapi_client/models/cu_ext_portal.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …dm_openapi_client/models/consistency_error_one_of13.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …idm_openapi_client/models/consistency_error_one_of2.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …napi_client/models/scim_sync_retention_mode_one_of1.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …anidm_openapi_client/models/scim_entry_post_generic.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | pykanidm/kanidm_openapi_client/models/filter_one_of4.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …nidm_openapi_client/models/password_feedback_one_of.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | pykanidm/kanidm_openapi_client/models/attribute.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …dm_openapi_client/models/consistency_error_one_of12.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …idm_openapi_client/models/consistency_error_one_of3.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | pykanidm/kanidm_openapi_client/models/auth_mech.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …anidm/kanidm_openapi_client/models/cu_session_token.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …m/kanidm_openapi_client/models/auth_allowed_one_of1.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …nidm_openapi_client/models/operation_error_one_of12.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …idm_openapi_client/models/consistency_error_one_of7.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | pykanidm/kanidm_openapi_client/models/totp_algo.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …/kanidm_openapi_client/models/identify_user_request.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …dm_openapi_client/models/consistency_error_one_of16.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …kanidm_openapi_client/models/identify_user_response.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | pykanidm/kanidm_openapi_client/models/app_link.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | pykanidm/kanidm_openapi_client/models/modify_one_of1.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | pykanidm/kanidm_openapi_client/models/uat_purpose.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …idm/kanidm_openapi_client/models/auth_state_one_of2.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …kanidm/kanidm_openapi_client/models/search_response.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …anidm_openapi_client/models/operation_error_one_of4.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | pykanidm/kanidm_openapi_client/models/ui_hint.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …m/kanidm_openapi_client/models/schema_error_one_of1.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | pykanidm/kanidm_openapi_client/models/passkey_detail.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …ent/models/identify_user_request_one_of_submit_code.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | pykanidm/kanidm_openapi_client/models/modify_list.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …nidm/kanidm_openapi_client/models/web_error_one_of1.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …penapi_client/models/credential_detail_type_one_of1.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …kanidm/kanidm_openapi_client/models/whoami_response.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …anidm_openapi_client/models/auth_credential_one_of1.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …m/kanidm_openapi_client/models/plugin_error_one_of1.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …m/kanidm_openapi_client/models/schema_error_one_of5.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …kanidm_openapi_client/models/auth_credential_one_of.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| HIGH | …m/kanidm_openapi_client/models/cu_reg_state_one_of2.py | 0 | kanidm api for interacting with the kanidm system. this is a work in progress. the version of the openapi document: 1.9. | STRING |
| 681 more matches not shown… | ||||
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 230 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 231 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 232 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 233 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 234 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 235 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 236 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 237 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 238 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 239 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 240 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 241 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 242 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 243 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 244 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 245 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 246 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 247 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 248 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 249 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 250 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 251 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 252 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 253 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 254 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 255 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 258 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 259 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 260 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 261 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 262 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 263 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 264 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 265 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 266 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 269 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 270 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 271 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 272 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 273 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 274 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 275 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 276 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 277 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 278 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 279 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 280 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 281 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 282 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 283 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 284 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 285 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 286 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 287 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 288 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 289 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 290 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 291 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 292 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 293 | CODE | |
| 827 more matches not shown… | ||||
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | pykanidm/kanidm_openapi_client/api_client.py | 339 | def sanitize_for_serialization(self, obj): | CODE |
| LOW | pykanidm/kanidm_openapi_client/api_client.py | 598 | def select_header_content_type(self, content_types): | CODE |
| LOW | …kanidm_openapi_client/models/credential_detail_type.py | 60 | def actual_instance_must_validate_oneof(cls, v): | CODE |
| LOW | pykanidm/kanidm_openapi_client/models/auth_state.py | 62 | def actual_instance_must_validate_oneof(cls, v): | CODE |
| LOW | pykanidm/kanidm_openapi_client/models/cu_reg_state.py | 71 | def actual_instance_must_validate_oneof(cls, v): | CODE |
| LOW | pykanidm/kanidm_openapi_client/models/cu_ext_portal.py | 57 | def actual_instance_must_validate_oneof(cls, v): | CODE |
| LOW | pykanidm/kanidm_openapi_client/models/attribute.py | 433 | def actual_instance_must_validate_oneof(cls, v): | CODE |
| LOW | …/kanidm_openapi_client/models/identify_user_request.py | 57 | def actual_instance_must_validate_oneof(cls, v): | CODE |
| LOW | …kanidm_openapi_client/models/identify_user_response.py | 63 | def actual_instance_must_validate_oneof(cls, v): | CODE |
| LOW | pykanidm/kanidm_openapi_client/models/uat_purpose.py | 55 | def actual_instance_must_validate_oneof(cls, v): | CODE |
| LOW | pykanidm/kanidm_openapi_client/models/auth_allowed.py | 64 | def actual_instance_must_validate_oneof(cls, v): | CODE |
| LOW | pykanidm/kanidm_openapi_client/models/web_error.py | 59 | def actual_instance_must_validate_oneof(cls, v): | CODE |
| LOW | …kanidm/kanidm_openapi_client/models/operation_error.py | 532 | def actual_instance_must_validate_oneof(cls, v): | CODE |
| LOW | pykanidm/kanidm_openapi_client/models/scim_attr.py | 63 | def actual_instance_must_validate_oneof(cls, v): | CODE |
| LOW | …nidm/kanidm_openapi_client/models/password_feedback.py | 111 | def actual_instance_must_validate_oneof(cls, v): | CODE |
| LOW | pykanidm/kanidm_openapi_client/models/schema_error.py | 82 | def actual_instance_must_validate_oneof(cls, v): | CODE |
| LOW | …nidm_openapi_client/models/scim_sync_retention_mode.py | 58 | def actual_instance_must_validate_oneof(cls, v): | CODE |
| LOW | …kanidm/kanidm_openapi_client/models/scim_sync_state.py | 55 | def actual_instance_must_validate_oneof(cls, v): | CODE |
| LOW | pykanidm/kanidm_openapi_client/models/scim_value.py | 60 | def actual_instance_must_validate_oneof(cls, v): | CODE |
| LOW | pykanidm/kanidm_openapi_client/models/modify.py | 59 | def actual_instance_must_validate_oneof(cls, v): | CODE |
| LOW | …anidm/kanidm_openapi_client/models/uat_status_state.py | 57 | def actual_instance_must_validate_oneof(cls, v): | CODE |
| LOW | pykanidm/kanidm_openapi_client/models/filter.py | 67 | def actual_instance_must_validate_oneof(cls, v): | CODE |
| LOW | …anidm/kanidm_openapi_client/models/b_tree_map_value.py | 63 | def actual_instance_must_validate_oneof(cls, v): | CODE |
| LOW | …kanidm/kanidm_openapi_client/models/auth_credential.py | 67 | def actual_instance_must_validate_oneof(cls, v): | CODE |
| LOW | pykanidm/kanidm_openapi_client/models/plugin_error.py | 61 | def actual_instance_must_validate_oneof(cls, v): | CODE |
| LOW | pykanidm/kanidm_openapi_client/models/auth_step.py | 62 | def actual_instance_must_validate_oneof(cls, v): | CODE |
| LOW | …nidm/kanidm_openapi_client/models/consistency_error.py | 113 | def actual_instance_must_validate_oneof(cls, v): | CODE |
| LOW | pykanidm/kanidm_openapi_client/api/recycle_bin_api.py | 107 | async def recycle_bin_get_with_http_info( | CODE |
| LOW | pykanidm/kanidm_openapi_client/api/recycle_bin_api.py | 172 | async def recycle_bin_get_without_preload_content( | CODE |
| LOW | pykanidm/kanidm_openapi_client/api/recycle_bin_api.py | 232 | def _recycle_bin_get_serialize( | CODE |
| LOW | pykanidm/kanidm_openapi_client/api/recycle_bin_api.py | 363 | async def recycle_bin_id_get_with_http_info( | CODE |
| LOW | pykanidm/kanidm_openapi_client/api/recycle_bin_api.py | 432 | async def recycle_bin_id_get_without_preload_content( | CODE |
| LOW | pykanidm/kanidm_openapi_client/api/recycle_bin_api.py | 496 | def _recycle_bin_id_get_serialize( | CODE |
| LOW | pykanidm/kanidm_openapi_client/api/recycle_bin_api.py | 561 | async def recycle_bin_revive_id_post( | CODE |
| LOW | pykanidm/kanidm_openapi_client/api/recycle_bin_api.py | 630 | async def recycle_bin_revive_id_post_with_http_info( | CODE |
| LOW | pykanidm/kanidm_openapi_client/api/recycle_bin_api.py | 699 | async def recycle_bin_revive_id_post_without_preload_content( | CODE |
| LOW | pykanidm/kanidm_openapi_client/api/recycle_bin_api.py | 763 | def _recycle_bin_revive_id_post_serialize( | CODE |
| LOW | pykanidm/kanidm_openapi_client/api/person_api.py | 109 | async def person_get_with_http_info( | CODE |
| LOW | pykanidm/kanidm_openapi_client/api/person_api.py | 174 | async def person_get_without_preload_content( | CODE |
| LOW | pykanidm/kanidm_openapi_client/api/person_api.py | 365 | async def person_id_delete_with_http_info( | CODE |
| LOW | pykanidm/kanidm_openapi_client/api/person_api.py | 434 | async def person_id_delete_without_preload_content( | CODE |
| LOW | pykanidm/kanidm_openapi_client/api/person_api.py | 498 | def _person_id_delete_serialize( | CODE |
| LOW | pykanidm/kanidm_openapi_client/api/person_api.py | 632 | async def person_id_get_with_http_info( | CODE |
| LOW | pykanidm/kanidm_openapi_client/api/person_api.py | 701 | async def person_id_get_without_preload_content( | CODE |
| LOW | pykanidm/kanidm_openapi_client/api/person_api.py | 903 | async def person_id_patch_with_http_info( | CODE |
| LOW | pykanidm/kanidm_openapi_client/api/person_api.py | 976 | async def person_id_patch_without_preload_content( | CODE |
| LOW | pykanidm/kanidm_openapi_client/api/person_api.py | 1044 | def _person_id_patch_serialize( | CODE |
| LOW | pykanidm/kanidm_openapi_client/api/person_api.py | 1125 | async def person_identify_user_post( | CODE |
| LOW | pykanidm/kanidm_openapi_client/api/person_api.py | 1198 | async def person_identify_user_post_with_http_info( | CODE |
| LOW | pykanidm/kanidm_openapi_client/api/person_api.py | 1271 | async def person_identify_user_post_without_preload_content( | CODE |
| LOW | pykanidm/kanidm_openapi_client/api/person_api.py | 1339 | def _person_identify_user_post_serialize( | CODE |
| LOW | pykanidm/kanidm_openapi_client/api/person_api.py | 1489 | async def person_post_with_http_info( | CODE |
| LOW | pykanidm/kanidm_openapi_client/api/person_api.py | 1558 | async def person_post_without_preload_content( | CODE |
| LOW | pykanidm/kanidm_openapi_client/api/person_api.py | 1769 | async def person_search_id_with_http_info( | CODE |
| LOW | pykanidm/kanidm_openapi_client/api/person_api.py | 1838 | async def person_search_id_without_preload_content( | CODE |
| LOW | pykanidm/kanidm_openapi_client/api/person_api.py | 1902 | def _person_search_id_serialize( | CODE |
| LOW | pykanidm/kanidm_openapi_client/api/person_attr_api.py | 114 | async def person_id_delete_attr_with_http_info( | CODE |
| LOW | pykanidm/kanidm_openapi_client/api/person_attr_api.py | 187 | async def person_id_delete_attr_without_preload_content( | CODE |
| LOW | pykanidm/kanidm_openapi_client/api/person_attr_api.py | 255 | def _person_id_delete_attr_serialize( | CODE |
| LOW | pykanidm/kanidm_openapi_client/api/person_attr_api.py | 396 | async def person_id_get_attr_with_http_info( | CODE |
| 484 more matches not shown… | ||||
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | Cargo.toml | 81 | # Single Largest Binary Maximum: 16GB | COMMENT |
| LOW | tools/mail_sender/src/main.rs | 1 | #![deny(warnings)] | COMMENT |
| LOW | tools/cli/src/cli/lib.rs | 1 | #![deny(warnings)] | COMMENT |
| LOW | tools/cli/src/cli/main.rs | 1 | #![deny(warnings)] | COMMENT |
| LOW | tools/cli/src/cli/webauthn/mod.rs | 1 | #[cfg(any(target_os = "linux", target_os = "macos"))] | COMMENT |
| LOW | tools/cli/src/cli/webauthn/mod.rs | 21 | /// * On other platforms, this uses Mozilla's `authenticator-rs`. | COMMENT |
| LOW | tools/cli/src/opt/kanidm.rs | 141 | AuthSessionExpiry { name: String, expiry: u32 }, | COMMENT |
| LOW | tools/cli/src/opt/kanidm.rs | 161 | /// from <https://crates.io/crates/fido-mds-tool> | COMMENT |
| LOW | tools/cli/src/opt/kanidm.rs | 181 | name: String, | COMMENT |
| LOW | tools/cli/src/opt/kanidm.rs | 221 | /// Create a new group | COMMENT |
| LOW | tools/cli/src/opt/kanidm.rs | 241 | /// mail address in the list is the `primary` and the remainder are aliases. Setting | COMMENT |
| LOW | tools/cli/src/opt/kanidm.rs | 261 | Rename { | COMMENT |
| LOW | tools/cli/src/opt/kanidm.rs | 321 | #[clap(flatten)] | COMMENT |
| LOW | tools/cli/src/opt/kanidm.rs | 381 | #[derive(Debug, Subcommand, Clone)] | COMMENT |
| LOW | tools/cli/src/opt/kanidm.rs | 401 | #[clap(long)] | COMMENT |
| LOW | tools/cli/src/opt/kanidm.rs | 421 | SoftlockReset { | COMMENT |
| LOW | tools/cli/src/opt/kanidm.rs | 501 | #[derive(Debug, Subcommand, Clone)] | COMMENT |
| LOW | tools/cli/src/opt/kanidm.rs | 561 | /// Manage radius access for this person | COMMENT |
| LOW | tools/cli/src/opt/kanidm.rs | 581 | Ssh { | COMMENT |
| LOW | tools/cli/src/opt/kanidm.rs | 621 | /// Reset and generate a new service account password. This password can NOT | COMMENT |
| LOW | tools/cli/src/opt/kanidm.rs | 641 | label: String, | COMMENT |
| LOW | tools/cli/src/opt/kanidm.rs | 721 | /// Manage sessions (user auth tokens) associated to this service account. | COMMENT |
| LOW | tools/cli/src/opt/kanidm.rs | 761 | /// (Deprecated - due for removal in v1.1.0-15) - Convert a service account into a person. This is used during the a | COMMENT |
| LOW | tools/cli/src/opt/kanidm.rs | 901 | // Set(), | COMMENT |
| LOW | tools/cli/src/opt/kanidm.rs | 921 | #[clap(name = "displayname")] | COMMENT |
| LOW | tools/cli/src/opt/kanidm.rs | 961 | group: String, | COMMENT |
| LOW | tools/cli/src/opt/kanidm.rs | 1041 | /// may not support it. You should request the client to enable PKCE! | COMMENT |
| LOW | tools/cli/src/opt/kanidm.rs | 1061 | EnablePublicLocalhost { name: String }, | COMMENT |
| LOW | tools/cli/src/opt/kanidm.rs | 1081 | /// have concerns a key is compromised, then you should revoke it instead. | COMMENT |
| LOW | tools/cli/src/opt/kanidm.rs | 1161 | new_max_queryable_attrs: usize, | COMMENT |
| LOW | tools/cli/src/opt/kanidm.rs | 1181 | SetAllowAccountRecovery { | COMMENT |
| LOW | tools/cli/src/opt/kanidm.rs | 1241 | /// List all configured IDM sync accounts | COMMENT |
| LOW | tools/cli/src/opt/kanidm.rs | 1281 | /// and are allowed to be modified by kanidm and users. Any attributes not listed in | COMMENT |
| LOW | tools/cli/src/opt/kanidm.rs | 1301 | /// Kanidm. ⚠️ This action can NOT be undone. Once complete, it is most likely | COMMENT |
| LOW | tools/cli/src/opt/kanidm.rs | 1321 | #[derive(Debug, Subcommand, Clone)] | COMMENT |
| LOW | tools/orca/src/opt.rs | 21 | #[clap(name = "generate")] | COMMENT |
| LOW | tools/orca/src/opt.rs | 61 | // TODO - support the extra uris field for replicated tests. | COMMENT |
| LOW | tools/orca/src/opt.rs | 81 | TestConnection { | COMMENT |
| LOW | tools/orca/src/state.rs | 61 | ExtendPrivilegedAuthExpiry, | COMMENT |
| LOW | tools/iam_migrations/ldap/src/opt.rs | 1 | use kanidm_proto::constants::DEFAULT_CLIENT_CONFIG_PATH; | COMMENT |
| LOW | tools/iam_migrations/ldap/src/opt.rs | 21 | /// No actions are taken on the kanidm instance, this is purely a dump of the | COMMENT |
| LOW | tools/iam_migrations/ldap/src/main.rs | 1 | #![deny(warnings)] | COMMENT |
| LOW | tools/iam_migrations/freeipa/src/opt.rs | 1 | use kanidm_proto::constants::DEFAULT_CLIENT_CONFIG_PATH; | COMMENT |
| LOW | tools/iam_migrations/freeipa/src/opt.rs | 21 | /// No actions are taken on the kanidm instance, this is purely a dump of the | COMMENT |
| LOW | tools/iam_migrations/freeipa/src/main.rs | 1 | #![deny(warnings)] | COMMENT |
| LOW | tools/iam_migrations/freeipa/src/main.rs | 561 | // | COMMENT |
| LOW | server/core/src/config.rs | 61 | /// - every 6th hours (four times a day) at 3 minutes past the hour, : | COMMENT |
| LOW | server/core/src/config.rs | 281 | COMMENT | |
| LOW | server/core/src/config.rs | 301 | COMMENT | |
| LOW | server/core/src/lib.rs | 1 | //! These contain the server "cores". These are able to startup the server | COMMENT |
| LOW | server/core/src/lib.rs | 101 | COMMENT | |
| LOW | server/core/src/crypto.rs | 41 | // |Method |Date |Symmetric| FM |DL Key| DL Group|Elliptic Curve|Hash| | COMMENT |
| LOW | server/core/src/https/oauth2.rs | 101 | // https://tools.ietf.org/html/rfc7636 | COMMENT |
| LOW | server/core/src/https/oauth2.rs | 121 | // | User- | | Authorization | | COMMENT |
| LOW | server/core/src/https/oauth2.rs | 141 | // | COMMENT |
| LOW | server/core/src/https/v1.rs | 3201 | .route( | COMMENT |
| LOW | server/core/src/https/manifest.rs | 61 | Rtl, | COMMENT |
| LOW | server/core/src/https/v1_scim.rs | 901 | // PUT Modifies a resource by replacing existing attributes with a | COMMENT |
| LOW | server/core/src/https/v1_scim.rs | 921 | // PATCH (Section 3.5.2), | COMMENT |
| LOW | server/core/src/https/v1_scim.rs | 941 | // Bulk /Bulk POST (Section 3.7) Bulk updates to one | COMMENT |
| 159 more matches not shown… | ||||
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| MEDIUM⚡ | server/lib/src/credential/softlock.rs | 30 | //! ┌────────────────────────┐ | COMMENT |
| MEDIUM⚡ | server/lib/src/credential/softlock.rs | 32 | //! ─└────────────────────────┘ | COMMENT |
| MEDIUM⚡ | server/lib/src/credential/softlock.rs | 35 | //! ┌─────┐ .─────. ┌────┐ │ | COMMENT |
| MEDIUM⚡ | server/lib/src/credential/softlock.rs | 37 | //! ┌────┴─────┴───────────────────────(count = 0)─────┴────┴┐ │ | COMMENT |
| MEDIUM⚡ | server/lib/src/credential/softlock.rs | 40 | //! │ ┌────────────────────────┐▲ │ | COMMENT |
| MEDIUM⚡ | server/lib/src/credential/softlock.rs | 42 | //! │ └────────────────────────┘│ │ | COMMENT |
| MEDIUM⚡ | server/lib/src/credential/softlock.rs | 45 | //! │ ├─────┬───────┬──┐ ▼ │ | COMMENT |
| MEDIUM⚡ | server/lib/src/credential/softlock.rs | 46 | //! │ │ │ Fail │ │ .─────. | COMMENT |
| MEDIUM⚡ | server/lib/src/credential/softlock.rs | 48 | //! ▼ .─────. └───────┘ │ ; Locked : | COMMENT |
| MEDIUM⚡ | server/lib/src/credential/softlock.rs | 49 | //! ┌────────────┐ ╱ ╲ └─────────▶: count > 0 ;◀─┤ | COMMENT |
| MEDIUM⚡ | server/lib/src/credential/softlock.rs | 50 | //! │Auth Success│◀─┬─────┬──(Unlocked ) ╲ ╱ │ | COMMENT |
| MEDIUM⚡ | server/lib/src/credential/softlock.rs | 51 | //! └────────────┘ │Valid│ `. ,' `. ,' │ | COMMENT |
| MEDIUM⚡ | server/lib/src/credential/softlock.rs | 52 | //! └─────┘ `───' `───' │ | COMMENT |
| MEDIUM⚡ | server/lib/src/credential/softlock.rs | 55 | //! └─────┬──────────────────────────┬┴┬───────┴──────────────────┐ | COMMENT |
| MEDIUM⚡ | server/lib/src/credential/softlock.rs | 57 | //! └──────────────────────────┘ └──────────────────────────┘ | COMMENT |
| MEDIUM | book/src/server_updates.md | 25 | # ------------------------ | COMMENT |
| MEDIUM | book/src/server_updates.md | 55 | # ------------------------ | COMMENT |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | server/testkit/tests/testkit/oauth2_test.rs | 162 | // Step 0 - get the openid discovery details and the public key. | COMMENT |
| LOW | server/testkit/tests/testkit/oauth2_test.rs | 243 | // Step 0 - get the jwks public key. | COMMENT |
| LOW | server/testkit/tests/testkit/oauth2_test.rs | 264 | // Step 1 - the Oauth2 Resource Server would send a redirect to the authorisation | COMMENT |
| LOW | server/testkit/tests/testkit/oauth2_test.rs | 320 | // Step 2 - we now send the consent get to the server which yields a redirect with a | COMMENT |
| LOW | server/testkit/tests/testkit/oauth2_test.rs | 361 | // Step 3 - the "resource server" then uses this state and code to directly contact | COMMENT |
| LOW | server/testkit/tests/testkit/oauth2_test.rs | 413 | // Step 4 - inspect the granted token. | COMMENT |
| LOW | server/testkit/tests/testkit/oauth2_test.rs | 468 | // Step 5 - check that the id_token (openid) matches the userinfo endpoint. | COMMENT |
| LOW | server/testkit/tests/testkit/oauth2_test.rs | 528 | // Step 6 - Show that our client can perform a client credentials grant | COMMENT |
| LOW | server/testkit/tests/testkit/oauth2_test.rs | 554 | // Step 7 - inspect the granted client credentials token. | COMMENT |
| LOW | server/testkit/tests/testkit/oauth2_test.rs | 858 | // Step 0 - get the jwks public key. | COMMENT |
| LOW | server/testkit/tests/testkit/oauth2_test.rs | 879 | // Step 1 - the Oauth2 Resource Server would send a redirect to the authorisation | COMMENT |
| LOW | server/testkit/tests/testkit/oauth2_test.rs | 939 | // Step 2 - we now send the consent get to the server which yields a redirect with a | COMMENT |
| LOW | server/testkit/tests/testkit/oauth2_test.rs | 985 | // Step 3 - the "resource server" then uses this state and code to directly contact | COMMENT |
| LOW | server/testkit/tests/testkit/oauth2_test.rs | 1013 | // Step 5 - check that the id_token (openid) matches the userinfo endpoint. | COMMENT |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | pykanidm/kanidm_openapi_client/rest.py | 91 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/api_client.py | 289 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/api_client.py | 339 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/api_client.py | 432 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/api_client.py | 479 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/api_client.py | 509 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/api_client.py | 548 | CODE | |
| LOW | pykanidm/tests/test_radius_token.py | 24 | CODE | |
| LOW | pykanidm/tests/test_openapi_spec.py | 85 | CODE |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | server/testkit/tests/testkit/integration.rs | 192 | assert!(str_output.contains("foo@bar.com")); | CODE |
| LOW | server/lib/src/idm/ldap.rs | 912 | .do_bind(idms, "admin@example.com", TEST_PASSWORD) | CODE |
| LOW | server/lib/src/idm/ldap.rs | 958 | .do_bind(idms, "admin@example.com", TEST_PASSWORD) | CODE |
| LOW | server/lib/src/idm/server.rs | 2939 | assert_eq!(tok_r.spn, "admin@example.com"); | CODE |
| LOW | server/lib/src/idm/server.rs | 2955 | assert_eq!(tok_g.spn, "admin@example.com"); | CODE |
| LOW | pykanidm/tests/test_radius_check_vlan.py | 49 | group=RadiusTokenGroup(spn="foo@bar.com", uuid="lol"), | CODE |
| LOW | book/src/integrations/oauth2/examples.md | 577 | kanidm person update '<user>' --legalname 'Personal Name' --mail 'user@example.com' | CODE |
| LOW | book/src/integrations/oauth2/examples.md | 994 | kanidm person update <user> --legalname "Personal Name" --mail "user@example.com" | CODE |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| HIGH | pykanidm/kanidm_openapi_client/rest.py | 160 | # Content-Type which generated by aiohttp | COMMENT |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | pykanidm/kanidm_openapi_client/configuration.py | 335 | def set_default(cls, default: Optional[Self]) -> None: | CODE |
| LOW | pykanidm/kanidm_openapi_client/__init__.py | 20 | __all__ = [ | CODE |
| LOW | pykanidm/tests/conftest.py | 47 | __all__ = [ | CODE |
| LOW⚡ | pykanidm/kanidm/openapi.py | 46 | __all__ = [ | CODE |
| LOW | pykanidm/kanidm/__init__.py | 150 | def _set_auth_token(self, token: Optional[str]) -> None: | CODE |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | tools/orca/src/models/latency_measurer.rs | 129 | // We need to check if the group was successfully created or not, and act accordingly! | COMMENT |
| LOW | server/lib/src/idm/ldap.rs | 571 | // we need to check if the entry exists at all (without the ava). | COMMENT |
| LOW | server/lib/src/server/access/search.rs | 338 | // Okay, now we need to check if the uuids line up. | COMMENT |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | pykanidm/kanidm_openapi_client/exceptions.py | 129 | except Exception: | CODE |
| LOW⚡ | pykanidm/kanidm/__init__.py | 675 | except Exception as error: | CODE |
| LOW | pykanidm/kanidm/radius/__init__.py | 134 | except Exception as error_message: # pylint: disable=broad-except | CODE |
| LOW | pykanidm/kanidm/radius/__init__.py | 193 | except Exception as error_message: # pylint: disable=broad-except | CODE |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | pykanidm/kanidm_openapi_client/configuration.py | 173 | CODE | |
| LOW | pykanidm/kanidm_openapi_client/api_client.py | 145 | CODE | |
| LOW | pykanidm/kanidm/openapi_codegen.py | 163 | CODE | |
| LOW | pykanidm/kanidm/__init__.py | 101 | CODE |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| MEDIUM | server/lib/src/server/access/mod.rs | 1262 | // because the schema system is well tested an robust. Instead we target | COMMENT |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| MEDIUM | scripts/pykanidm/integration_test.py | 33 | # Define the new working directory | COMMENT |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| MEDIUM | book/src/developers/faq.md | 17 | ## Is the project going to create a microservice like architecture? | COMMENT |