Repository navigation
chore: stop depending on httparrot's expiring TLS certificate - #945
Conversation
yordis
commented
Sep 28, 2026
- The server certificate bundled with httparrot 1.5.0 expired on 2026-09-23, which breaks every HTTPS adapter test on master and on all open PRs (e.g. chore(deps): bump mint from 1.10.0 to 1.10.1 in the prod group across 1 directory #944).
- Upstream has no fix, and httparrot hardcodes its certificate paths, so issuing a fresh chain on every test run keeps CI from breaking again whenever a bundled certificate goes stale.
Signed-off-by: Yordis Prieto <yordis.prieto@gmail.com>
PR SummaryLow Risk Overview Adds Finch, Gun, Hackney, Httpc, Mint (and commented ibrowse SSL) now point Reviewed by Cursor Bugbot for commit 096687e. Bugbot is set up for automated code reviews on this repo. Configure here. |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Represent the IPv4 SAN value as a byte list to ensure certificate generation succeeds.
Review effort: Lite
Findings: 1
Open (1)
What changed in this PR
Updates HTTPS adapter tests to generate fresh TLS certificates instead of relying on httparrot’s expired certificate.
Changes:
- Generates per-run CA and server certificates.
- Reconfigures httparrot and test servers with generated TLS assets.
- Updates adapters to trust the generated CA.
| File | Summary |
|---|---|
test/test_helper.exs |
Initializes TLS materials and restarts httparrot HTTPS. |
test/tesla/adapter/mint_test.exs |
Uses generated TLS configuration. |
test/tesla/adapter/ibrowse_test.exs |
Updates the TLS example. |
test/tesla/adapter/httpc_test.exs |
Uses the generated CA. |
test/tesla/adapter/hackney_test.exs |
Uses the generated CA. |
test/tesla/adapter/gun_test.exs |
Uses generated CA material. |
test/tesla/adapter/finch_test.exs |
Uses the generated CA. |
test/support/tls.ex |
Generates and stores test TLS certificates. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
