feat: support tls - #948
NguyenHoangSon96 wants to merge 2 commits into
Conversation
73fd6c3 to
7c780a6
Compare
|
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## master #948 +/- ##
============================================
- Coverage 88.71% 87.92% -0.79%
- Complexity 735 736 +1
============================================
Files 174 175 +1
Lines 7285 7397 +112
Branches 422 437 +15
============================================
+ Hits 6463 6504 +41
- Misses 688 757 +69
- Partials 134 136 +2 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The TLS loader rejects common valid key and store configurations, while the committed certificates expire in 2027.
Review effort: Balanced
Findings: 4
Open (6)
Hard-coded RSA factory rejects EC private keys · New Password fallback prevents loading passwordless PKCS#12 files · New Password is ignored for encrypted private keys · New PEM CA certificates are rejected by filename extension · New Server test certificates expire after 365 days · New Client test certificate expires after 365 days · New
What changed in this PR
Adds custom TLS and mutual-TLS configuration for the Java client.
Changes:
- Adds PEM and PKCS#12 certificate configuration.
- Builds custom SSL contexts for OkHttp.
- Adds TLS fixtures and integration tests.
| File | Description |
|---|---|
pom.xml |
Excludes TLS fixtures from license checks. |
CHANGELOG.md |
Announces TLS/mTLS support. |
client-utils/.../TlsUtils.java |
Loads certificates and builds TLS managers. |
client/.../InfluxDBClientOptions.java |
Exposes TLS builder options. |
client/.../InfluxDBClientTest.java |
Tests TLS and mTLS handshakes. |
client/.../InfluxDBClientOptionsTest.java |
Tests TLS option configuration. |
client-core/.../RestClientTest.java |
Reorders imports. |
client/.../tls/generate-self-signed-cert.sh |
Generates test credentials. |
client/.../tls/influxdb.{crt,key,p12} |
Provides server fixtures. |
client/.../tls/other-server.{crt,key,p12} |
Provides untrusted-server fixtures. |
client/.../tls/client.{crt,key,p12} |
Provides client fixtures. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
9d4caf7 to
0d4faec
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
TLS configuration does not satisfy combined-file and plain-HTTP requirements, and PEM certificate chains are truncated.
Review effort: Balanced
Findings: 4
Open (5)
Resolved since last review (6)
PEM CA certificates are rejected by filename extension Password is ignored for encrypted private keys Password fallback prevents loading passwordless PKCS#12 files Hard-coded RSA factory rejects EC private keys Client test certificate expires after 365 days Server test certificates expire after 365 days
a8f9b53 to
c9fbd2f
Compare
b89500f to
e76d259
Compare


Closes #947
Proposed Changes
Checklist
mvn testcompletes successfully