fix(server): missing root cert (#14970)

#### PR Dependency Tree


* **PR #14970** 👈

This tree was auto-generated by
[Charcoal](https://github.com/danerwilliams/charcoal)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
* Updated TLS library dependencies with pinned version constraints
across multiple packages
* Removed `tls-rustls` feature from sqlx configurations in backend and
frontend packages
  * Removed unused `sqlx` dependency from mobile native package
* Refined HTTPS client configuration with embedded certificate roots and
added validation test

<!-- review_stack_entry_start -->

[![Review Change
Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/toeverything/AFFiNE/pull/14970)

<!-- review_stack_entry_end -->

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
This commit is contained in:
DarkSky
2026-05-15 01:02:07 +08:00
committed by GitHub
parent d9cebdfc95
commit 3416de1e4d
8 changed files with 27 additions and 22 deletions
Generated
+3 -13
View File
@@ -143,7 +143,6 @@ dependencies = [
"mermaid-rs-renderer",
"objc2",
"objc2-foundation",
"sqlx",
"thiserror 2.0.18",
"tokio",
"typst",
@@ -237,6 +236,7 @@ dependencies = [
"rand 0.9.4",
"rayon",
"reqwest",
"rustls",
"schemars",
"serde",
"serde_json",
@@ -246,6 +246,7 @@ dependencies = [
"tokio",
"url",
"v_htmlescape",
"webpki-roots",
"y-octo",
]
@@ -6225,7 +6226,6 @@ dependencies = [
"memchr",
"once_cell",
"percent-encoding",
"rustls",
"serde",
"serde_json",
"sha2",
@@ -6235,7 +6235,6 @@ dependencies = [
"tokio-stream",
"tracing",
"url",
"webpki-roots 0.26.11",
]
[[package]]
@@ -8048,7 +8047,7 @@ dependencies = [
"rustls-pki-types",
"ureq-proto",
"utf8-zero",
"webpki-roots 1.0.6",
"webpki-roots",
]
[[package]]
@@ -8410,15 +8409,6 @@ dependencies = [
"rustls-pki-types",
]
[[package]]
name = "webpki-roots"
version = "0.26.11"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "521bc38abb08001b01866da9f51eb7c5d647a19260e00054a8c7fd5f9e57f7a9"
dependencies = [
"webpki-roots 1.0.6",
]
[[package]]
name = "webpki-roots"
version = "1.0.6"
-1
View File
@@ -110,7 +110,6 @@ resolver = "3"
"migrate",
"runtime-tokio",
"sqlite",
"tls-rustls",
] }
strum_macros = "0.27.0"
symphonia = { version = "0.5", features = ["all", "opt-simd"] }
+3 -1
View File
@@ -9,13 +9,13 @@ version = "1.0.0"
crate-type = ["cdylib"]
[dependencies]
aes-gcm = { workspace = true }
affine_common = { workspace = true, features = [
"doc-loader",
"hashcash",
"napi",
"ydoc-loader",
] }
aes-gcm = { workspace = true }
anyhow = { workspace = true }
base64-simd = { workspace = true }
chrono = { workspace = true }
@@ -38,6 +38,7 @@ reqwest = { version = "0.13.3", default-features = false, features = [
"blocking",
"rustls",
] }
rustls = "0.23"
schemars = { workspace = true }
serde = { workspace = true, features = ["derive"] }
serde_json = { workspace = true }
@@ -46,6 +47,7 @@ sha3 = { workspace = true }
tiktoken-rs = { workspace = true }
url = { workspace = true }
v_htmlescape = { workspace = true }
webpki-roots = "1"
y-octo = { workspace = true, features = ["large_refs"] }
[target.'cfg(not(target_os = "linux"))'.dependencies]
+21
View File
@@ -412,11 +412,25 @@ fn build_pinned_client(url: &Url, addrs: &[SocketAddr], timeout: Duration) -> An
.timeout(timeout)
.no_proxy()
.redirect(reqwest::redirect::Policy::none())
.tls_backend_preconfigured(webpki_tls_config()?)
.resolve_to_addrs(host, addrs)
.build()
.context("failed to build http client")
}
fn webpki_tls_config() -> AnyResult<rustls::ClientConfig> {
let root_store = rustls::RootCertStore {
roots: webpki_roots::TLS_SERVER_ROOTS.to_vec(),
};
Ok(
rustls::ClientConfig::builder_with_provider(rustls::crypto::aws_lc_rs::default_provider().into())
.with_safe_default_protocol_versions()
.context("failed to build tls protocol config")?
.with_root_certificates(root_store)
.with_no_client_auth(),
)
}
fn build_headers(headers: Option<&HashMap<String, String>>) -> AnyResult<HeaderMap> {
let mut out = HeaderMap::new();
let Some(headers) = headers else {
@@ -623,6 +637,13 @@ mod tests {
assert!(!is_blocked_ip("2002:0808:0808::1".parse().unwrap()));
}
#[test]
fn builds_https_client_with_embedded_roots() {
let url = Url::parse("https://example.com/").unwrap();
let addrs = ["93.184.216.34:443".parse().unwrap()];
build_pinned_client(&url, &addrs, Duration::from_secs(1)).unwrap();
}
#[test]
fn inspects_png_dimensions_without_decode() {
let png = base64_simd::STANDARD
@@ -22,7 +22,6 @@ affine_nbstore = { workspace = true }
anyhow = { workspace = true }
base64-simd = { workspace = true }
chrono = { workspace = true }
sqlx = { workspace = true }
thiserror = { workspace = true }
tokio = { workspace = true, features = ["rt-multi-thread"] }
uniffi = { workspace = true, features = ["cli", "tokio"] }
-2
View File
@@ -21,7 +21,6 @@ sqlx = { workspace = true, default-features = false, features = [
"migrate",
"runtime-tokio",
"sqlite",
"tls-rustls",
] }
thiserror = { workspace = true }
tokio = { workspace = true, features = ["full"] }
@@ -52,6 +51,5 @@ sqlx = { workspace = true, default-features = false, features = [
"migrate",
"runtime-tokio",
"sqlite",
"tls-rustls",
] }
tokio = { workspace = true, features = ["full"] }
@@ -28,7 +28,6 @@ sqlx = { workspace = true, default-features = false, features = [
"migrate",
"runtime-tokio",
"sqlite",
"tls-rustls",
] }
thiserror = { workspace = true }
tokio = { workspace = true, features = ["full"] }
@@ -48,7 +47,6 @@ sqlx = { workspace = true, default-features = false, features = [
"migrate",
"runtime-tokio",
"sqlite",
"tls-rustls",
] }
tokio = { workspace = true, features = ["full"] }
@@ -19,7 +19,6 @@ sqlx = { workspace = true, default-features = false, features = [
"migrate",
"runtime-tokio",
"sqlite",
"tls-rustls",
] }
tokio = { workspace = true, features = ["full"] }
@@ -33,6 +32,5 @@ sqlx = { workspace = true, default-features = false, features = [
"migrate",
"runtime-tokio",
"sqlite",
"tls-rustls",
] }
tokio = { workspace = true, features = ["full"] }