Time out every connection, and scope --allow-invalid-certs #6

Merged
jcoffey-dev merged 2 commits from fix/connection-safety into main 2026-09-30 18:34:51 +00:00
Owner

Phase 1, items 4 and 6 of the inbuxa-migrate roadmap.

Timeouts on every connection. No HTTP agent had a timeout, so a dropped connection hung a JMAP, DAV, EWS or Graph run, or an export, forever. Every agent now takes its settings from src/net.rs: 30s to connect, 60s for the request headers, 5 min for the server's first byte, and 30 min for a whole response body. ureq counts the body as one budget, not per read, so 30 min covers the 512 MiB limit at about 300 KB/s. A JMAP upload's send budget grows with its size (a 2 min floor plus 64 KiB/s). A timeout is a transport error, which every client already retried; tests pin that down per client.

--allow-invalid-certs is scoped. It used to switch verification off for everything, including the Microsoft sign-in endpoints. It now covers only the host of --url, or for EWS Autodiscover with no --url, the mailbox's domain and then only the EWS endpoint found. Microsoft and Google sign-in and cloud hosts are always verified. Each client keeps a verifying agent, plus a relaxed one only when the flag applies, and picks per request by host. Documented in docs/usage.md and the flag's help text.

Checks: cargo fmt --check, cargo clippy --all-targets -D warnings, cargo test (1339 passed, 61 ignored live tests, which compile but need Docker).

Phase 1, items 4 and 6 of the inbuxa-migrate roadmap. **Timeouts on every connection.** No HTTP agent had a timeout, so a dropped connection hung a JMAP, DAV, EWS or Graph run, or an export, forever. Every agent now takes its settings from `src/net.rs`: 30s to connect, 60s for the request headers, 5 min for the server's first byte, and 30 min for a whole response body. ureq counts the body as one budget, not per read, so 30 min covers the 512 MiB limit at about 300 KB/s. A JMAP upload's send budget grows with its size (a 2 min floor plus 64 KiB/s). A timeout is a transport error, which every client already retried; tests pin that down per client. **`--allow-invalid-certs` is scoped.** It used to switch verification off for everything, including the Microsoft sign-in endpoints. It now covers only the host of `--url`, or for EWS Autodiscover with no `--url`, the mailbox's domain and then only the EWS endpoint found. Microsoft and Google sign-in and cloud hosts are always verified. Each client keeps a verifying agent, plus a relaxed one only when the flag applies, and picks per request by host. Documented in `docs/usage.md` and the flag's help text. Checks: `cargo fmt --check`, `cargo clippy --all-targets -D warnings`, `cargo test` (1339 passed, 61 ignored live tests, which compile but need Docker).
jcoffey-dev added 2 commits 2026-09-30 18:32:01 +00:00
No ureq agent set a timeout, and ureq sets none by default, so a connection
dropped silently mid-transfer (a NAT or load-balancer idle drop) hung a JMAP,
DAV, EWS or Graph run, or an export, with no error, and the retry logic never
got a chance to run. IMAP and ManageSieve already had read timeouts.

Every agent now takes its settings from a new net module: 30s to connect,
60s to send the request headers, 5 minutes for the server's first byte, and
30 minutes for a whole response body, which ureq counts as one budget for the
body rather than per read: enough for the 512 MiB limit at about 300 KB/s.
A JMAP upload's send budget grows with its size, from a 2 minute floor at an
assumed 64 KiB/s worst case.

A timeout is a transport error, and every client already retries those, so a
stalled transfer is now abandoned and retried. Tests pin that down for each
client. The TLS setup the seven agents repeated moves to one helper.
Scope --allow-invalid-certs to the server the user named
ci / test (pull_request) Skipped
github/ci (branch) GitHub Actions
ci / github (pull_request) Successful in 2m33s
ci / announce (pull_request) Skipped
234b3203d7
The flag switched certificate checks off for every connection in the run.
That included the Microsoft sign-in endpoints, so a user passing it for a
self-signed source also sent refresh tokens, device codes and EWS client
secrets over unverified TLS. It also covered the export target, and any host
a server redirected to or named for its API, uploads or downloads.

It now applies only where the user pointed it: the host of --url, for the
source of an import or the target of an export. For an Exchange import with
no --url, it covers the mailbox's own domain, where on-premises Autodiscover
looks, and then only the EWS endpoint Autodiscover finds. The Microsoft and
Google sign-in and cloud hosts are always verified, with or without the flag.

Each HTTP client keeps a verifying agent and, only when the flag applies, a
second one that accepts invalid certificates, and picks per request by host.
The sign-in modules no longer take the flag at all. Autodiscover v2, which is
Microsoft's own service, is always verified.
jcoffey-dev merged commit 14a797cd65 into main 2026-09-30 18:34:51 +00:00
jcoffey-dev deleted branch fix/connection-safety 2026-09-30 18:34:51 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: inbuxa/inbuxa-migrate#6