Skip to content

chore: stop depending on httparrot's expiring TLS certificate - #945

Merged
yordis merged 1 commit into
masterfrom
yordis/fix-expired-test-tls-cert
Sep 28, 2026
Merged

yordis merged 1 commit into
masterfrom
yordis/fix-expired-test-tls-cert

Conversation

@yordis

@yordis yordis commented Sep 28, 2026

Copy link
Copy Markdown
Member

Signed-off-by: Yordis Prieto <yordis.prieto@gmail.com>
@yordis
yordis requested a review from a team as a code owner September 28, 2026 09:17
Copilot AI lite review requested due to automatic review settings September 28, 2026 09:17
@cursor

cursor Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

PR Summary

Low Risk
Test-only infrastructure change; production library code is untouched.

Overview
HTTPS adapter tests no longer trust or serve httparrot’s bundled, expiring certs (which broke CI after 2026-09-23).

Adds Tesla.TestSupport.TLS, which uses :public_key.pkix_test_data/1 once per run to mint a localhost SAN chain, writes CA/server/key PEMs under a temp dir, and exposes paths via persistent_term. test_helper.exs regenerates material, stops the default :https listener, and restarts Cowboy on the httparrot HTTPS port with the new certfile / keyfile.

Finch, Gun, Hackney, Httpc, Mint (and commented ibrowse SSL) now point cacertfile (and Mint’s ad-hoc TLS Cowboy setups) at Tesla.TestSupport.TLS instead of :code.priv_dir(:httparrot)/ssl/...; Mint drops the old httparrot_cacertfile/0 helper.

Reviewed by Cursor Bugbot for commit 096687e. Bugbot is set up for automated code reviews on this repo. Configure here.

@yordis yordis changed the title test: stop depending on httparrot's expiring TLS certificate chore: stop depending on httparrot's expiring TLS certificate Sep 28, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Represent the IPv4 SAN value as a byte list to ensure certificate generation succeeds.

Review effort: Lite
Findings: 1 High severity

Open (1)
What changed in this PR

Updates HTTPS adapter tests to generate fresh TLS certificates instead of relying on httparrot’s expired certificate.

Changes:

  • Generates per-run CA and server certificates.
  • Reconfigures httparrot and test servers with generated TLS assets.
  • Updates adapters to trust the generated CA.
File Summary
test/​test_helper.exs Initializes TLS materials and restarts httparrot HTTPS.
test/​tesla/​adapter/​mint_test.exs Uses generated TLS configuration.
test/​tesla/​adapter/​ibrowse_test.exs Updates the TLS example.
test/​tesla/​adapter/​httpc_test.exs Uses the generated CA.
test/​tesla/​adapter/​hackney_test.exs Uses the generated CA.
test/​tesla/​adapter/​gun_test.exs Uses generated CA material.
test/​tesla/​adapter/​finch_test.exs Uses the generated CA.
test/​support/​tls.ex Generates and stores test TLS certificates.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread test/support/tls.ex
@yordis
yordis merged commit 2dd5448 into master Sep 28, 2026
15 of 16 checks passed
@yordis
yordis deleted the yordis/fix-expired-test-tls-cert branch September 28, 2026 11:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants