summaryrefslogtreecommitdiff
path: root/src
diff options
context:
space:
mode:
authoromnom62 <omnom62@outlook.com>2026-08-11 17:01:58 +1000
committerJohn Estabrook <jestabro@vyos.io>2026-08-26 13:33:34 -0500
commitc489a19e454a9be5438fc16e26e62407a0d64f49 (patch)
tree6f2e5bf50d0ff780ef248cc81ed787f299c2aef8 /src
parent0cdf7e696b4deb3c3103a596bfe4d4f167dcf4b7 (diff)
downloadvyos-1x-c489a19e454a9be5438fc16e26e62407a0d64f49.tar.gz
vyos-1x-c489a19e454a9be5438fc16e26e62407a0d64f49.zip
http-api: T8989: linter fixes
Diffstat (limited to 'src')
-rwxr-xr-xsrc/conf_mode/service_https.py8
-rw-r--r--src/services/api/rest/routers.py8
2 files changed, 13 insertions, 3 deletions
diff --git a/src/conf_mode/service_https.py b/src/conf_mode/service_https.py
index f66ce043c..b1381eca5 100755
--- a/src/conf_mode/service_https.py
+++ b/src/conf_mode/service_https.py
@@ -114,7 +114,9 @@ def verify(https):
'Do not use them in a production environment!')
if dict_search('certificates.verify_client', https) is not None:
if dict_search('certificates.ca_certificate', https) is None:
- raise ConfigError('CA certificate must be configured for mTLS client verification')
+ raise ConfigError(
+ 'CA certificate must be configured for mTLS client verification'
+ )
# Check if server port is already in use by a different application
listen_address = ['0.0.0.0']
@@ -216,7 +218,9 @@ def generate(https):
https['certificates'].update(tmp_path)
# Write mTLS CA chain if verify-client is configured
- if dict_search('certificates.verify_client', https) and dict_search('certificates.ca_certificate', https):
+ if dict_search('certificates.verify_client', https) and dict_search(
+ 'certificates.ca_certificate', https
+ ):
ca_name = https['certificates']['ca_certificate']
pki_ca = dict_search(f'pki.ca.{ca_name}', https)
if pki_ca:
diff --git a/src/services/api/rest/routers.py b/src/services/api/rest/routers.py
index 55967f57d..0973ad145 100644
--- a/src/services/api/rest/routers.py
+++ b/src/services/api/rest/routers.py
@@ -101,7 +101,12 @@ def check_auth(key_list, key):
return key_id
-def auth_required(data: ApiModel, x_api_key: Optional[str] = Header(None), authorization: Optional[str] = Header(None), x_client_verify: Optional[str] = Header(None)):
+def auth_required(
+ data: ApiModel,
+ x_api_key: Optional[str] = Header(None),
+ authorization: Optional[str] = Header(None),
+ x_client_verify: Optional[str] = Header(None),
+):
session = SessionState()
# mTLS: client certificate verified by nginx against configured CA
if x_client_verify == 'SUCCESS':
@@ -1032,6 +1037,7 @@ def traceroute_op(data: TracerouteModel):
return success(res)
+
@router.post('/token')
def token_op(data: ApiModel):
session = SessionState()