fix(server): missing root cert (#14970)
#### PR Dependency Tree * **PR #14970** 👈 This tree was auto-generated by [Charcoal](https://github.com/danerwilliams/charcoal) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated TLS library dependencies with pinned version constraints across multiple packages * Removed `tls-rustls` feature from sqlx configurations in backend and frontend packages * Removed unused `sqlx` dependency from mobile native package * Refined HTTPS client configuration with embedded certificate roots and added validation test <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/toeverything/AFFiNE/pull/14970) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai -->
This commit is contained in:
16
Cargo.lock
generated
16
Cargo.lock
generated
@@ -143,7 +143,6 @@ dependencies = [
|
|||||||
"mermaid-rs-renderer",
|
"mermaid-rs-renderer",
|
||||||
"objc2",
|
"objc2",
|
||||||
"objc2-foundation",
|
"objc2-foundation",
|
||||||
"sqlx",
|
|
||||||
"thiserror 2.0.18",
|
"thiserror 2.0.18",
|
||||||
"tokio",
|
"tokio",
|
||||||
"typst",
|
"typst",
|
||||||
@@ -237,6 +236,7 @@ dependencies = [
|
|||||||
"rand 0.9.4",
|
"rand 0.9.4",
|
||||||
"rayon",
|
"rayon",
|
||||||
"reqwest",
|
"reqwest",
|
||||||
|
"rustls",
|
||||||
"schemars",
|
"schemars",
|
||||||
"serde",
|
"serde",
|
||||||
"serde_json",
|
"serde_json",
|
||||||
@@ -246,6 +246,7 @@ dependencies = [
|
|||||||
"tokio",
|
"tokio",
|
||||||
"url",
|
"url",
|
||||||
"v_htmlescape",
|
"v_htmlescape",
|
||||||
|
"webpki-roots",
|
||||||
"y-octo",
|
"y-octo",
|
||||||
]
|
]
|
||||||
|
|
||||||
@@ -6225,7 +6226,6 @@ dependencies = [
|
|||||||
"memchr",
|
"memchr",
|
||||||
"once_cell",
|
"once_cell",
|
||||||
"percent-encoding",
|
"percent-encoding",
|
||||||
"rustls",
|
|
||||||
"serde",
|
"serde",
|
||||||
"serde_json",
|
"serde_json",
|
||||||
"sha2",
|
"sha2",
|
||||||
@@ -6235,7 +6235,6 @@ dependencies = [
|
|||||||
"tokio-stream",
|
"tokio-stream",
|
||||||
"tracing",
|
"tracing",
|
||||||
"url",
|
"url",
|
||||||
"webpki-roots 0.26.11",
|
|
||||||
]
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
@@ -8048,7 +8047,7 @@ dependencies = [
|
|||||||
"rustls-pki-types",
|
"rustls-pki-types",
|
||||||
"ureq-proto",
|
"ureq-proto",
|
||||||
"utf8-zero",
|
"utf8-zero",
|
||||||
"webpki-roots 1.0.6",
|
"webpki-roots",
|
||||||
]
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
@@ -8410,15 +8409,6 @@ dependencies = [
|
|||||||
"rustls-pki-types",
|
"rustls-pki-types",
|
||||||
]
|
]
|
||||||
|
|
||||||
[[package]]
|
|
||||||
name = "webpki-roots"
|
|
||||||
version = "0.26.11"
|
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
|
||||||
checksum = "521bc38abb08001b01866da9f51eb7c5d647a19260e00054a8c7fd5f9e57f7a9"
|
|
||||||
dependencies = [
|
|
||||||
"webpki-roots 1.0.6",
|
|
||||||
]
|
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "webpki-roots"
|
name = "webpki-roots"
|
||||||
version = "1.0.6"
|
version = "1.0.6"
|
||||||
|
|||||||
@@ -110,7 +110,6 @@ resolver = "3"
|
|||||||
"migrate",
|
"migrate",
|
||||||
"runtime-tokio",
|
"runtime-tokio",
|
||||||
"sqlite",
|
"sqlite",
|
||||||
"tls-rustls",
|
|
||||||
] }
|
] }
|
||||||
strum_macros = "0.27.0"
|
strum_macros = "0.27.0"
|
||||||
symphonia = { version = "0.5", features = ["all", "opt-simd"] }
|
symphonia = { version = "0.5", features = ["all", "opt-simd"] }
|
||||||
|
|||||||
@@ -9,13 +9,13 @@ version = "1.0.0"
|
|||||||
crate-type = ["cdylib"]
|
crate-type = ["cdylib"]
|
||||||
|
|
||||||
[dependencies]
|
[dependencies]
|
||||||
|
aes-gcm = { workspace = true }
|
||||||
affine_common = { workspace = true, features = [
|
affine_common = { workspace = true, features = [
|
||||||
"doc-loader",
|
"doc-loader",
|
||||||
"hashcash",
|
"hashcash",
|
||||||
"napi",
|
"napi",
|
||||||
"ydoc-loader",
|
"ydoc-loader",
|
||||||
] }
|
] }
|
||||||
aes-gcm = { workspace = true }
|
|
||||||
anyhow = { workspace = true }
|
anyhow = { workspace = true }
|
||||||
base64-simd = { workspace = true }
|
base64-simd = { workspace = true }
|
||||||
chrono = { workspace = true }
|
chrono = { workspace = true }
|
||||||
@@ -38,6 +38,7 @@ reqwest = { version = "0.13.3", default-features = false, features = [
|
|||||||
"blocking",
|
"blocking",
|
||||||
"rustls",
|
"rustls",
|
||||||
] }
|
] }
|
||||||
|
rustls = "0.23"
|
||||||
schemars = { workspace = true }
|
schemars = { workspace = true }
|
||||||
serde = { workspace = true, features = ["derive"] }
|
serde = { workspace = true, features = ["derive"] }
|
||||||
serde_json = { workspace = true }
|
serde_json = { workspace = true }
|
||||||
@@ -46,6 +47,7 @@ sha3 = { workspace = true }
|
|||||||
tiktoken-rs = { workspace = true }
|
tiktoken-rs = { workspace = true }
|
||||||
url = { workspace = true }
|
url = { workspace = true }
|
||||||
v_htmlescape = { workspace = true }
|
v_htmlescape = { workspace = true }
|
||||||
|
webpki-roots = "1"
|
||||||
y-octo = { workspace = true, features = ["large_refs"] }
|
y-octo = { workspace = true, features = ["large_refs"] }
|
||||||
|
|
||||||
[target.'cfg(not(target_os = "linux"))'.dependencies]
|
[target.'cfg(not(target_os = "linux"))'.dependencies]
|
||||||
|
|||||||
@@ -412,11 +412,25 @@ fn build_pinned_client(url: &Url, addrs: &[SocketAddr], timeout: Duration) -> An
|
|||||||
.timeout(timeout)
|
.timeout(timeout)
|
||||||
.no_proxy()
|
.no_proxy()
|
||||||
.redirect(reqwest::redirect::Policy::none())
|
.redirect(reqwest::redirect::Policy::none())
|
||||||
|
.tls_backend_preconfigured(webpki_tls_config()?)
|
||||||
.resolve_to_addrs(host, addrs)
|
.resolve_to_addrs(host, addrs)
|
||||||
.build()
|
.build()
|
||||||
.context("failed to build http client")
|
.context("failed to build http client")
|
||||||
}
|
}
|
||||||
|
|
||||||
|
fn webpki_tls_config() -> AnyResult<rustls::ClientConfig> {
|
||||||
|
let root_store = rustls::RootCertStore {
|
||||||
|
roots: webpki_roots::TLS_SERVER_ROOTS.to_vec(),
|
||||||
|
};
|
||||||
|
Ok(
|
||||||
|
rustls::ClientConfig::builder_with_provider(rustls::crypto::aws_lc_rs::default_provider().into())
|
||||||
|
.with_safe_default_protocol_versions()
|
||||||
|
.context("failed to build tls protocol config")?
|
||||||
|
.with_root_certificates(root_store)
|
||||||
|
.with_no_client_auth(),
|
||||||
|
)
|
||||||
|
}
|
||||||
|
|
||||||
fn build_headers(headers: Option<&HashMap<String, String>>) -> AnyResult<HeaderMap> {
|
fn build_headers(headers: Option<&HashMap<String, String>>) -> AnyResult<HeaderMap> {
|
||||||
let mut out = HeaderMap::new();
|
let mut out = HeaderMap::new();
|
||||||
let Some(headers) = headers else {
|
let Some(headers) = headers else {
|
||||||
@@ -623,6 +637,13 @@ mod tests {
|
|||||||
assert!(!is_blocked_ip("2002:0808:0808::1".parse().unwrap()));
|
assert!(!is_blocked_ip("2002:0808:0808::1".parse().unwrap()));
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn builds_https_client_with_embedded_roots() {
|
||||||
|
let url = Url::parse("https://example.com/").unwrap();
|
||||||
|
let addrs = ["93.184.216.34:443".parse().unwrap()];
|
||||||
|
build_pinned_client(&url, &addrs, Duration::from_secs(1)).unwrap();
|
||||||
|
}
|
||||||
|
|
||||||
#[test]
|
#[test]
|
||||||
fn inspects_png_dimensions_without_decode() {
|
fn inspects_png_dimensions_without_decode() {
|
||||||
let png = base64_simd::STANDARD
|
let png = base64_simd::STANDARD
|
||||||
|
|||||||
@@ -22,7 +22,6 @@ affine_nbstore = { workspace = true }
|
|||||||
anyhow = { workspace = true }
|
anyhow = { workspace = true }
|
||||||
base64-simd = { workspace = true }
|
base64-simd = { workspace = true }
|
||||||
chrono = { workspace = true }
|
chrono = { workspace = true }
|
||||||
sqlx = { workspace = true }
|
|
||||||
thiserror = { workspace = true }
|
thiserror = { workspace = true }
|
||||||
tokio = { workspace = true, features = ["rt-multi-thread"] }
|
tokio = { workspace = true, features = ["rt-multi-thread"] }
|
||||||
uniffi = { workspace = true, features = ["cli", "tokio"] }
|
uniffi = { workspace = true, features = ["cli", "tokio"] }
|
||||||
|
|||||||
@@ -21,7 +21,6 @@ sqlx = { workspace = true, default-features = false, features = [
|
|||||||
"migrate",
|
"migrate",
|
||||||
"runtime-tokio",
|
"runtime-tokio",
|
||||||
"sqlite",
|
"sqlite",
|
||||||
"tls-rustls",
|
|
||||||
] }
|
] }
|
||||||
thiserror = { workspace = true }
|
thiserror = { workspace = true }
|
||||||
tokio = { workspace = true, features = ["full"] }
|
tokio = { workspace = true, features = ["full"] }
|
||||||
@@ -52,6 +51,5 @@ sqlx = { workspace = true, default-features = false, features = [
|
|||||||
"migrate",
|
"migrate",
|
||||||
"runtime-tokio",
|
"runtime-tokio",
|
||||||
"sqlite",
|
"sqlite",
|
||||||
"tls-rustls",
|
|
||||||
] }
|
] }
|
||||||
tokio = { workspace = true, features = ["full"] }
|
tokio = { workspace = true, features = ["full"] }
|
||||||
|
|||||||
@@ -28,7 +28,6 @@ sqlx = { workspace = true, default-features = false, features = [
|
|||||||
"migrate",
|
"migrate",
|
||||||
"runtime-tokio",
|
"runtime-tokio",
|
||||||
"sqlite",
|
"sqlite",
|
||||||
"tls-rustls",
|
|
||||||
] }
|
] }
|
||||||
thiserror = { workspace = true }
|
thiserror = { workspace = true }
|
||||||
tokio = { workspace = true, features = ["full"] }
|
tokio = { workspace = true, features = ["full"] }
|
||||||
@@ -48,7 +47,6 @@ sqlx = { workspace = true, default-features = false, features = [
|
|||||||
"migrate",
|
"migrate",
|
||||||
"runtime-tokio",
|
"runtime-tokio",
|
||||||
"sqlite",
|
"sqlite",
|
||||||
"tls-rustls",
|
|
||||||
] }
|
] }
|
||||||
tokio = { workspace = true, features = ["full"] }
|
tokio = { workspace = true, features = ["full"] }
|
||||||
|
|
||||||
|
|||||||
@@ -19,7 +19,6 @@ sqlx = { workspace = true, default-features = false, features = [
|
|||||||
"migrate",
|
"migrate",
|
||||||
"runtime-tokio",
|
"runtime-tokio",
|
||||||
"sqlite",
|
"sqlite",
|
||||||
"tls-rustls",
|
|
||||||
] }
|
] }
|
||||||
tokio = { workspace = true, features = ["full"] }
|
tokio = { workspace = true, features = ["full"] }
|
||||||
|
|
||||||
@@ -33,6 +32,5 @@ sqlx = { workspace = true, default-features = false, features = [
|
|||||||
"migrate",
|
"migrate",
|
||||||
"runtime-tokio",
|
"runtime-tokio",
|
||||||
"sqlite",
|
"sqlite",
|
||||||
"tls-rustls",
|
|
||||||
] }
|
] }
|
||||||
tokio = { workspace = true, features = ["full"] }
|
tokio = { workspace = true, features = ["full"] }
|
||||||
|
|||||||
Reference in New Issue
Block a user