diff options
| author | Yuriy Andamasov <yuriy@vyos.io> | 2026-10-04 12:46:17 +0300 |
|---|---|---|
| committer | Yuriy Andamasov <yuriy@vyos.io> | 2026-10-04 12:46:17 +0300 |
| commit | 69160aae61b3dc00a31d5980919d665e02f4c417 (patch) | |
| tree | e7eaeb15fae305a698a4b5b95fbc4942400b6fbd /src/utils/vyos-hostsd-client | |
| parent | 7f7c730cb415f6b1b22abe5788a10e02c50778ad (diff) | |
| download | vyos-1x-fix/T8955-http-api-verify-tls.tar.gz vyos-1x-fix/T8955-http-api-verify-tls.zip | |
http-api-client: T8955: leave warning handling to the callerfix/T8955-http-api-verify-tls
Address the round-2 adversarial-review finding: warnings.catch_warnings()
mutates the process-global filter list for the duration of the block (still
the case on Python 3.13), so scoping suppression inside the library was not
actually isolated.
- http_api_client no longer touches warning filters at all. The
_suppress_insecure_warning helper is removed and post() calls
session.post directly again. The unused warnings, contextmanager and
urllib3 imports are dropped. The class docstring now states that callers
disabling verification own InsecureRequestWarning handling. The OSError
wrapping and verify_tls validation are unchanged.
- config_sync ignores InsecureRequestWarning in its __main__ block only,
before opmode.run(). That one-shot op-mode process deliberately connects
without verification (verify_tls=False) until T9396. Importing the module
adds no filter.
🤖 Generated by [robots](https://vyos.io)
Diffstat (limited to 'src/utils/vyos-hostsd-client')
0 files changed, 0 insertions, 0 deletions
