From d53c7fc85cd17bc89d567f2ac73dd75bbc5539ed Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Zo=C3=AB?= Date: Wed, 26 Aug 2026 12:53:10 +0200 Subject: [PATCH] fix(bitwarden): add SSL context for API requests and set device identifiers --- bitwarden_client.py | 20 ++++++++++++++++---- main.py | 6 ++++++ 2 files changed, 22 insertions(+), 4 deletions(-) diff --git a/bitwarden_client.py b/bitwarden_client.py index a003e94..93a7d26 100644 --- a/bitwarden_client.py +++ b/bitwarden_client.py @@ -3,6 +3,8 @@ Bitwarden/Vaultwarden REST API client. Handles authentication, vault sync, and API communication. """ import json +import os +import ssl from base64 import b64decode, b64encode from typing import Optional, Tuple @@ -11,6 +13,15 @@ import aiohttp from crypto import BitwardenCrypto, PinCrypto +def _get_ssl_context(): + ssl_ctx = ssl.create_default_context() + for ca_path in ["/etc/ssl/certs/ca-certificates.crt", "/etc/ssl/certs/ca-bundle.crt"]: + if os.path.exists(ca_path): + ssl_ctx.load_verify_locations(ca_path) + break + return ssl_ctx + + # Default URLs BITWARDEN_API_BASE = "https://api.bitwarden.com" BITWARDEN_IDENTITY_BASE = "https://identity.bitwarden.com" @@ -91,7 +102,7 @@ class BitwardenClient: async with aiohttp.ClientSession() as session: async with session.request( - method, url, headers=headers, json=data, params=params + method, url, headers=headers, json=data, params=params, ssl=_get_ssl_context() ) as resp: text = await resp.text() if resp.status >= 400: @@ -157,8 +168,9 @@ class BitwardenClient: "username": email, "password": master_password_hash, "scope": "api offline_access", - "client_id": "connector", + "client_id": "web", "deviceType": DEVICE_TYPE, + "deviceIdentifier": "decky-vaultwarden", "deviceName": "decky-vaultwarden", } @@ -173,7 +185,7 @@ class BitwardenClient: # Use form data instead of JSON async with aiohttp.ClientSession() as session: async with session.post( - url, data=data, headers=headers + url, data=data, headers=headers, ssl=_get_ssl_context() ) as resp: text = await resp.text() if resp.status >= 400: @@ -225,7 +237,7 @@ class BitwardenClient: async with aiohttp.ClientSession() as session: async with session.post( - url, data=data, headers=headers + url, data=data, headers=headers, ssl=_get_ssl_context() ) as resp: text = await resp.text() if resp.status >= 400: diff --git a/main.py b/main.py index f05bf3a..d64ec77 100644 --- a/main.py +++ b/main.py @@ -15,6 +15,12 @@ py_modules_dir = os.path.join(plugin_dir, "py_modules") sys.path.insert(0, py_modules_dir) sys.path.insert(0, plugin_dir) +if "SSL_CERT_FILE" not in os.environ: + for ca_path in ["/etc/ssl/certs/ca-certificates.crt", "/etc/ssl/certs/ca-bundle.crt"]: + if os.path.exists(ca_path): + os.environ["SSL_CERT_FILE"] = ca_path + break + def _ensure_deps(): try: import cryptography # noqa: F401