Files
inbuxa-migrate/tests
jcoffey-dev 234b3203d7
ci / test (pull_request) Skipped
github/ci (branch) GitHub Actions
ci / github (pull_request) Successful in 2m33s
ci / announce (pull_request) Skipped
Scope --allow-invalid-certs to the server the user named
The flag switched certificate checks off for every connection in the run.
That included the Microsoft sign-in endpoints, so a user passing it for a
self-signed source also sent refresh tokens, device codes and EWS client
secrets over unverified TLS. It also covered the export target, and any host
a server redirected to or named for its API, uploads or downloads.

It now applies only where the user pointed it: the host of --url, for the
source of an import or the target of an export. For an Exchange import with
no --url, it covers the mailbox's own domain, where on-premises Autodiscover
looks, and then only the EWS endpoint Autodiscover finds. The Microsoft and
Google sign-in and cloud hosts are always verified, with or without the flag.

Each HTTP client keeps a verifying agent and, only when the flag applies, a
second one that accepts invalid certificates, and picks per request by host.
The sign-in modules no longer take the flag at all. Autodiscover v2, which is
Microsoft's own service, is always verified.
2026-09-30 11:31:44 -07:00
..
2026-09-30 10:09:10 -07:00
2026-09-30 10:09:10 -07:00
2026-09-30 10:09:10 -07:00
2026-09-30 10:09:10 -07:00
2026-09-30 10:09:10 -07:00
2026-09-30 10:09:10 -07:00
2026-09-30 10:09:10 -07:00
2026-09-30 10:09:10 -07:00
2026-09-30 10:09:10 -07:00
2026-05-29 18:02:15 +02:00
2026-09-30 10:09:10 -07:00
2026-09-30 10:09:10 -07:00
2026-09-30 10:09:10 -07:00
2026-09-30 10:09:10 -07:00
2026-09-30 10:09:10 -07:00
2026-09-30 10:09:10 -07:00
2026-09-30 10:09:10 -07:00
2026-09-30 10:09:10 -07:00