Scope --allow-invalid-certs to the server the user named
The flag switched certificate checks off for every connection in the run. That included the Microsoft sign-in endpoints, so a user passing it for a self-signed source also sent refresh tokens, device codes and EWS client secrets over unverified TLS. It also covered the export target, and any host a server redirected to or named for its API, uploads or downloads. It now applies only where the user pointed it: the host of --url, for the source of an import or the target of an export. For an Exchange import with no --url, it covers the mailbox's own domain, where on-premises Autodiscover looks, and then only the EWS endpoint Autodiscover finds. The Microsoft and Google sign-in and cloud hosts are always verified, with or without the flag. Each HTTP client keeps a verifying agent and, only when the flag applies, a second one that accepts invalid certificates, and picks per request by host. The sign-in modules no longer take the flag at all. Autodiscover v2, which is Microsoft's own service, is always verified.
This commit is contained in:
@@ -21,6 +21,7 @@ use inbuxa_migrate::exchange_graph::recurrence::convert_patterned_recurrence;
|
||||
use inbuxa_migrate::exchange_graph::retry::{HttpClass, classify_http_status};
|
||||
use inbuxa_migrate::exchange_graph::types::Surfaces;
|
||||
use inbuxa_migrate::jmap::http::RetryPolicy;
|
||||
use inbuxa_migrate::net::CertOverride;
|
||||
use mockito::{Matcher, Server};
|
||||
use serde_json::json;
|
||||
|
||||
@@ -28,7 +29,11 @@ static INIT: Once = Once::new();
|
||||
|
||||
fn client_with_retries(retries: u32) -> GraphClient {
|
||||
INIT.call_once(|| {});
|
||||
GraphClient::new("BEARER".to_owned(), RetryPolicy::new(retries), false)
|
||||
GraphClient::new(
|
||||
"BEARER".to_owned(),
|
||||
RetryPolicy::new(retries),
|
||||
CertOverride::none(),
|
||||
)
|
||||
}
|
||||
|
||||
fn url_message_collection(server_url: &str, folder: &str, top: usize) -> String {
|
||||
@@ -1681,7 +1686,11 @@ fn graph_client_retries_after_401_when_bearer_is_swapped() {
|
||||
.expect(1)
|
||||
.create();
|
||||
let base = server.url();
|
||||
let client = GraphClient::new("EXPIRED".to_owned(), RetryPolicy::new(0), false);
|
||||
let client = GraphClient::new(
|
||||
"EXPIRED".to_owned(),
|
||||
RetryPolicy::new(0),
|
||||
CertOverride::none(),
|
||||
);
|
||||
let url = format!("{base}/me");
|
||||
let err = client.get(&url, Accept::Json).unwrap_err();
|
||||
assert!(matches!(err, GraphError::Auth(_)));
|
||||
|
||||
Reference in New Issue
Block a user