plugin.api.websocket: use certifi's cacert.pem#4977
Merged
gravyboat merged 1 commit intoNov 17, 2022
Conversation
- Add `certifi` as a direct dependency (already defined by `requests`) and don't set a version range - Set the `ca_certs` SSL option in `WebsocketClient` which defaults to the CA certs file bundled by `certifi`, similar to HTTPS requests made by `requests`
9892d3d to
78be83b
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
certifias a direct dependency (already defined byrequests) and don't set a version rangeca_certsSSL option inWebsocketClientwhich defaults to the CA certs file bundled bycertifi, similar to HTTPS requests made byrequestsResolves streamlink/streamlink-appimage#1
While
requestsuses the bundledcacert.pemCA certificates file by thecertifidependency (viacertifi.where()) for all HTTPS requests being made by Streamlink (since Streamlink doesn't set any custom paths),websocket-clientdefaults to the system's CA certs which get loaded by OpenSSL. Depending on the system config, this can cause issues, and it's also inconsistent with HTTPS requests made byrequests. Streamlink should therefore load the samecacert.pemwhen making secure websocket connections viawebsocket-client, likerequestsdoes for all HTTPS requests.Similar to
requestsand itsREQUESTS_CA_BUNDLE/CURL_CA_BUNDLEenv vars,WEBSOCKET_CLIENT_CA_BUNDLEcan be set to override the default path.I have no idea though what changing this does to OpenSSL's
SSL_CERT_FILEenv var and whether this will still be supported.