"""Guards on outbound TLS verification. A trusted-LAN Ollama is often served over HTTPS with a certificate from a CA the user installed on their own machines rather than one the public web knows. `httpx` verifies against `certifi` alone, so such an endpoint failed here while `curl` and the browser accepted it. `app/tlstrust.py` unions the machine's CA store with certifi's; these tests keep that union honest in both directions — it must not lose a public CA, and it must not stop verifying. Everything here is local. Nothing in this file opens a socket, so the suite still runs with no network. python -m pytest tests/test_tls_trust.py -v """ import ast import ssl from pathlib import Path import certifi import pytest from app import tlstrust APP = Path(__file__).resolve().parents[1] / "app" def test_verification_is_not_weakened(): """The point of the change is *where* trust comes from, never whether it is checked. A context that skipped verification would make every one of these endpoints reachable, including a hostile one.""" context = tlstrust.ssl_context() assert context.verify_mode is ssl.CERT_REQUIRED assert context.check_hostname is True def test_context_is_built_once(): assert tlstrust.ssl_context() is tlstrust.ssl_context() def test_public_certificate_authorities_are_still_trusted(): """The union is a strict superset of what httpx trusted before. Swapping certifi for the platform store instead would quietly break public endpoints on an image whose system store is empty or stale.""" ours = {c for c in tlstrust.ssl_context().get_ca_certs(binary_form=True)} certifi_only = ssl.create_default_context(cafile=certifi.where()) theirs = {c for c in certifi_only.get_ca_certs(binary_form=True)} assert theirs, "certifi's bundle came back empty; the comparison proves nothing" assert theirs <= ours, f"{len(theirs - ours)} certifi roots are missing from the union" def _async_client_calls(path: Path): """Every `httpx.AsyncClient(...)` construction in a module, as AST nodes.""" tree = ast.parse(path.read_text()) for node in ast.walk(tree): if not isinstance(node, ast.Call): continue func = node.func if ( isinstance(func, ast.Attribute) and func.attr == "AsyncClient" and isinstance(func.value, ast.Name) and func.value.id == "httpx" ): yield node @pytest.mark.parametrize( "module", ["providers/openai_compatible.py", "routers/settings.py"], ) def test_every_http_client_uses_the_shared_context(module): """Checked in the source rather than at runtime, because the failure this catches is a *new* client added later without the context — which no existing test would exercise, and which would work perfectly until someone pointed it at a LAN endpoint.""" calls = list(_async_client_calls(APP / module)) assert calls, f"no httpx.AsyncClient found in {module} — has it been renamed?" for call in calls: keywords = {kw.arg for kw in call.keywords} assert "verify" in keywords, ( f"{module}:{call.lineno} builds an httpx.AsyncClient without " f"verify=tlstrust.ssl_context()" ) def test_no_other_module_builds_its_own_client(): """If a third module starts making outbound requests, it has to be added to the list above rather than inheriting certifi-only trust by default.""" known = {APP / "providers/openai_compatible.py", APP / "routers/settings.py"} found = {p for p in APP.rglob("*.py") if any(_async_client_calls(p))} assert found == known, f"unexpected httpx.AsyncClient call sites: {found - known}"