Skip to content

fix: honor TLS verification settings in HTTP clients - #142

Open
abhinavrastogi2627 wants to merge 1 commit into
typesense:masterfrom
abhinavrastogi2627:fix/http-client-verify
Open

abhinavrastogi2627 wants to merge 1 commit into
typesense:masterfrom
abhinavrastogi2627:fix/http-client-verify

Conversation

@abhinavrastogi2627

Copy link
Copy Markdown

Summary

Pass the existing Configuration.verify value to HTTPX when constructing both API clients. After the HTTPX migration, this setting was stored but ignored, so custom CA bundles and explicit verify=False had no effect. The default remains certificate verification enabled.

The async source is updated and the sync source regenerated with utils/run-unasync.py. Eight regression cases exercise both clients: effective TLS verification modes, loading a configured CA bundle through the real SSL context builder, and rejection of a missing CA file. Six of those cases fail on the unchanged base.

Fixes #139. This addresses runtime forwarding; the ConfigDict.verify annotation change remains covered separately by #136.

Validation

  • 61 tests passed across SSL configuration, API calls, configuration, and configuration validation on Python 3.13.
  • uv run ruff check src/typesense tests/api_call_ssl_test.py
  • Ruff formatting checks passed for the changed files.
  • uv run mypy src/typesense: no issues in 104 source files.
  • uv run python utils/run-unasync.py --check

The full Typesense-server integration suite was not run. String CA paths retain HTTPX 0.28.1's existing deprecation warning; this change does not alter HTTPX's accepted verification values.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

pass verify through to the client

1 participant