Files
hermes-agent/agent/ssl_verify.py

53 lines
1.7 KiB
Python

"""TLS verify resolution for httpx/OpenAI provider clients."""
from __future__ import annotations
import logging
import os
import ssl
from pathlib import Path
from typing import Any, Optional
logger = logging.getLogger(__name__)
_CA_BUNDLE_ENV_VARS = ("HERMES_CA_BUNDLE", "SSL_CERT_FILE", "REQUESTS_CA_BUNDLE", "CURL_CA_BUNDLE")
def _coerce_insecure(ssl_verify: Any) -> bool:
if ssl_verify is False:
return True
return isinstance(ssl_verify, str) and ssl_verify.strip().lower() in {"false", "0", "no", "off"}
def resolve_httpx_verify(
*,
ca_bundle: Optional[str] = None,
ssl_verify: Any = None,
base_url: str = "",
) -> bool | ssl.SSLContext:
"""Resolve httpx ``verify``: ``ssl_verify: false`` > explicit ``ca_bundle`` >
CA-bundle env vars > ``True`` (certifi default). ``base_url`` only feeds the warning."""
if _coerce_insecure(ssl_verify):
logger.warning(
"TLS certificate verification DISABLED (ssl_verify: false) for %s — "
"this is intended for local development only and is unsafe on any "
"network you do not fully control.",
base_url or "a custom provider endpoint",
)
return False
effective_ca = (ca_bundle or "").strip()
for env_var in _CA_BUNDLE_ENV_VARS:
if effective_ca:
break
effective_ca = os.getenv(env_var, "").strip()
if effective_ca:
ca_path = str(Path(effective_ca).expanduser())
if os.path.isfile(ca_path):
return ssl.create_default_context(cafile=ca_path)
logger.warning(
"CA bundle path does not exist: %s — falling back to default certificates",
effective_ca,
)
return True