Scope --allow-invalid-certs to the server the user named
The flag switched certificate checks off for every connection in the run. That included the Microsoft sign-in endpoints, so a user passing it for a self-signed source also sent refresh tokens, device codes and EWS client secrets over unverified TLS. It also covered the export target, and any host a server redirected to or named for its API, uploads or downloads. It now applies only where the user pointed it: the host of --url, for the source of an import or the target of an export. For an Exchange import with no --url, it covers the mailbox's own domain, where on-premises Autodiscover looks, and then only the EWS endpoint Autodiscover finds. The Microsoft and Google sign-in and cloud hosts are always verified, with or without the flag. Each HTTP client keeps a verifying agent and, only when the flag applies, a second one that accepts invalid certificates, and picks per request by host. The sign-in modules no longer take the flag at all. Autodiscover v2, which is Microsoft's own service, is always verified.
This commit is contained in:
@@ -22,6 +22,7 @@ use inbuxa_migrate::exchange_ews::xml::{
|
||||
get_item_body, sync_folder_items_body,
|
||||
};
|
||||
use inbuxa_migrate::jmap::http::{Auth, RetryPolicy};
|
||||
use inbuxa_migrate::net::CertOverride;
|
||||
use mockito::Matcher;
|
||||
|
||||
const TXT_XML: &str = "text/xml; charset=utf-8";
|
||||
@@ -33,7 +34,7 @@ fn client(retries: u32) -> EwsClient {
|
||||
token: "t".to_owned(),
|
||||
},
|
||||
RetryPolicy::new(retries),
|
||||
false,
|
||||
CertOverride::none(),
|
||||
)
|
||||
}
|
||||
|
||||
@@ -63,7 +64,7 @@ fn autodiscover_v2_returns_global_endpoint() {
|
||||
let _ = server;
|
||||
let url = "https://outlook.office365.com/EWS/Exchange.asmx";
|
||||
assert!(inbuxa_migrate::exchange_ews::autodiscover::is_fully_qualified_ews_url(url));
|
||||
let r = discover(Some(url), None, None, false).unwrap();
|
||||
let r = discover(Some(url), None, None, &CertOverride::none()).unwrap();
|
||||
assert_eq!(r.source, DiscoverySource::SuppliedUrl);
|
||||
assert_eq!(r.ews_url, url);
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user