fix: convert CA bundle path to ssl.SSLContext to avoid httpx deprecation warning
httpx emits a DeprecationWarning when verify=<str> is passed, recommending ssl.SSLContext instead. This affected both our httpx client factories and the caldav library passthrough. Changed get_nextcloud_ssl_verify() to return bool | ssl.SSLContext instead of bool | str by constructing an SSLContext when NEXTCLOUD_CA_BUNDLE is set. All downstream consumers (httpx, caldav) natively accept ssl.SSLContext. Also fixed app password endpoint tests that used overly broad MagicMock (auto-generated truthy nextcloud_ca_bundle attribute). Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.6
parent
1707b2e6e1
commit
1a4486a388
@@ -2,8 +2,10 @@
|
||||
|
||||
import logging
|
||||
import os
|
||||
import ssl
|
||||
from unittest.mock import patch
|
||||
|
||||
import certifi
|
||||
import httpx
|
||||
import pytest
|
||||
|
||||
@@ -64,17 +66,26 @@ class TestGetNextcloudSSLVerify:
|
||||
result = get_nextcloud_ssl_verify()
|
||||
assert result is False
|
||||
|
||||
def test_ca_bundle_returns_path(self, tmp_path):
|
||||
ca_file = tmp_path / "ca.pem"
|
||||
ca_file.write_text(
|
||||
"-----BEGIN CERTIFICATE-----\ntest\n-----END CERTIFICATE-----\n"
|
||||
)
|
||||
def test_ca_bundle_returns_ssl_context(self):
|
||||
ca_bundle = certifi.where()
|
||||
with patch(
|
||||
"nextcloud_mcp_server.config.get_settings",
|
||||
return_value=Settings(nextcloud_ca_bundle=str(ca_file)),
|
||||
return_value=Settings(nextcloud_ca_bundle=ca_bundle),
|
||||
):
|
||||
result = get_nextcloud_ssl_verify()
|
||||
assert result == str(ca_file)
|
||||
assert isinstance(result, ssl.SSLContext)
|
||||
|
||||
def test_ca_bundle_ssl_context_has_loaded_certs(self):
|
||||
"""SSLContext created from CA bundle should have loaded certificates."""
|
||||
ca_bundle = certifi.where()
|
||||
with patch(
|
||||
"nextcloud_mcp_server.config.get_settings",
|
||||
return_value=Settings(nextcloud_ca_bundle=ca_bundle),
|
||||
):
|
||||
result = get_nextcloud_ssl_verify()
|
||||
assert isinstance(result, ssl.SSLContext)
|
||||
stats = result.cert_store_stats()
|
||||
assert stats["x509_ca"] > 0
|
||||
|
||||
def test_verify_false_takes_precedence_over_ca_bundle(self, tmp_path):
|
||||
"""When verify_ssl=False, ca_bundle is ignored (False wins)."""
|
||||
|
||||
Reference in New Issue
Block a user