Repository navigation
feat: support tls - #948
NguyenHoangSon96 wants to merge 2 commits into
Conversation
73fd6c3 to
7c780a6
Compare
|
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## master #948 +/- ##
============================================
- Coverage 88.71% 87.93% -0.79%
- Complexity 735 736 +1
============================================
Files 174 175 +1
Lines 7285 7400 +115
Branches 422 437 +15
============================================
+ Hits 6463 6507 +44
- Misses 688 757 +69
- Partials 134 136 +2 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The TLS loader rejects common valid key and store configurations, while the committed certificates expire in 2027.
Review effort: Balanced
Findings: 4
Open (6)
Hard-coded RSA factory rejects EC private keys · New Password fallback prevents loading passwordless PKCS#12 files · New Password is ignored for encrypted private keys · New PEM CA certificates are rejected by filename extension · New Server test certificates expire after 365 days · New Client test certificate expires after 365 days · New
What changed in this PR
Adds custom TLS and mutual-TLS configuration for the Java client.
Changes:
- Adds PEM and PKCS#12 certificate configuration.
- Builds custom SSL contexts for OkHttp.
- Adds TLS fixtures and integration tests.
| File | Description |
|---|---|
pom.xml |
Excludes TLS fixtures from license checks. |
CHANGELOG.md |
Announces TLS/mTLS support. |
client-utils/.../TlsUtils.java |
Loads certificates and builds TLS managers. |
client/.../InfluxDBClientOptions.java |
Exposes TLS builder options. |
client/.../InfluxDBClientTest.java |
Tests TLS and mTLS handshakes. |
client/.../InfluxDBClientOptionsTest.java |
Tests TLS option configuration. |
client-core/.../RestClientTest.java |
Reorders imports. |
client/.../tls/generate-self-signed-cert.sh |
Generates test credentials. |
client/.../tls/influxdb.{crt,key,p12} |
Provides server fixtures. |
client/.../tls/other-server.{crt,key,p12} |
Provides untrusted-server fixtures. |
client/.../tls/client.{crt,key,p12} |
Provides client fixtures. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
9d4caf7 to
0d4faec
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
TLS configuration does not satisfy combined-file and plain-HTTP requirements, and PEM certificate chains are truncated.
Review effort: Balanced
Findings: 4
Open (5)
Resolved since last review (6)
PEM CA certificates are rejected by filename extension Password is ignored for encrypted private keys Password fallback prevents loading passwordless PKCS#12 files Hard-coded RSA factory rejects EC private keys Client test certificate expires after 365 days Server test certificates expire after 365 days
a8f9b53 to
c9fbd2f
Compare
b89500f to
e76d259
Compare
77d2ae5 to
d9501f7
Compare


Closes #947
Proposed Changes
Checklist
mvn testcompletes successfully