fix(bitwarden): add SSL context for API requests and set device identifiers
This commit is contained in:
+16
-4
@@ -3,6 +3,8 @@ Bitwarden/Vaultwarden REST API client.
|
|||||||
Handles authentication, vault sync, and API communication.
|
Handles authentication, vault sync, and API communication.
|
||||||
"""
|
"""
|
||||||
import json
|
import json
|
||||||
|
import os
|
||||||
|
import ssl
|
||||||
from base64 import b64decode, b64encode
|
from base64 import b64decode, b64encode
|
||||||
from typing import Optional, Tuple
|
from typing import Optional, Tuple
|
||||||
|
|
||||||
@@ -11,6 +13,15 @@ import aiohttp
|
|||||||
from crypto import BitwardenCrypto, PinCrypto
|
from crypto import BitwardenCrypto, PinCrypto
|
||||||
|
|
||||||
|
|
||||||
|
def _get_ssl_context():
|
||||||
|
ssl_ctx = ssl.create_default_context()
|
||||||
|
for ca_path in ["/etc/ssl/certs/ca-certificates.crt", "/etc/ssl/certs/ca-bundle.crt"]:
|
||||||
|
if os.path.exists(ca_path):
|
||||||
|
ssl_ctx.load_verify_locations(ca_path)
|
||||||
|
break
|
||||||
|
return ssl_ctx
|
||||||
|
|
||||||
|
|
||||||
# Default URLs
|
# Default URLs
|
||||||
BITWARDEN_API_BASE = "https://api.bitwarden.com"
|
BITWARDEN_API_BASE = "https://api.bitwarden.com"
|
||||||
BITWARDEN_IDENTITY_BASE = "https://identity.bitwarden.com"
|
BITWARDEN_IDENTITY_BASE = "https://identity.bitwarden.com"
|
||||||
@@ -91,7 +102,7 @@ class BitwardenClient:
|
|||||||
|
|
||||||
async with aiohttp.ClientSession() as session:
|
async with aiohttp.ClientSession() as session:
|
||||||
async with session.request(
|
async with session.request(
|
||||||
method, url, headers=headers, json=data, params=params
|
method, url, headers=headers, json=data, params=params, ssl=_get_ssl_context()
|
||||||
) as resp:
|
) as resp:
|
||||||
text = await resp.text()
|
text = await resp.text()
|
||||||
if resp.status >= 400:
|
if resp.status >= 400:
|
||||||
@@ -157,8 +168,9 @@ class BitwardenClient:
|
|||||||
"username": email,
|
"username": email,
|
||||||
"password": master_password_hash,
|
"password": master_password_hash,
|
||||||
"scope": "api offline_access",
|
"scope": "api offline_access",
|
||||||
"client_id": "connector",
|
"client_id": "web",
|
||||||
"deviceType": DEVICE_TYPE,
|
"deviceType": DEVICE_TYPE,
|
||||||
|
"deviceIdentifier": "decky-vaultwarden",
|
||||||
"deviceName": "decky-vaultwarden",
|
"deviceName": "decky-vaultwarden",
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -173,7 +185,7 @@ class BitwardenClient:
|
|||||||
# Use form data instead of JSON
|
# Use form data instead of JSON
|
||||||
async with aiohttp.ClientSession() as session:
|
async with aiohttp.ClientSession() as session:
|
||||||
async with session.post(
|
async with session.post(
|
||||||
url, data=data, headers=headers
|
url, data=data, headers=headers, ssl=_get_ssl_context()
|
||||||
) as resp:
|
) as resp:
|
||||||
text = await resp.text()
|
text = await resp.text()
|
||||||
if resp.status >= 400:
|
if resp.status >= 400:
|
||||||
@@ -225,7 +237,7 @@ class BitwardenClient:
|
|||||||
|
|
||||||
async with aiohttp.ClientSession() as session:
|
async with aiohttp.ClientSession() as session:
|
||||||
async with session.post(
|
async with session.post(
|
||||||
url, data=data, headers=headers
|
url, data=data, headers=headers, ssl=_get_ssl_context()
|
||||||
) as resp:
|
) as resp:
|
||||||
text = await resp.text()
|
text = await resp.text()
|
||||||
if resp.status >= 400:
|
if resp.status >= 400:
|
||||||
|
|||||||
@@ -15,6 +15,12 @@ py_modules_dir = os.path.join(plugin_dir, "py_modules")
|
|||||||
sys.path.insert(0, py_modules_dir)
|
sys.path.insert(0, py_modules_dir)
|
||||||
sys.path.insert(0, plugin_dir)
|
sys.path.insert(0, plugin_dir)
|
||||||
|
|
||||||
|
if "SSL_CERT_FILE" not in os.environ:
|
||||||
|
for ca_path in ["/etc/ssl/certs/ca-certificates.crt", "/etc/ssl/certs/ca-bundle.crt"]:
|
||||||
|
if os.path.exists(ca_path):
|
||||||
|
os.environ["SSL_CERT_FILE"] = ca_path
|
||||||
|
break
|
||||||
|
|
||||||
def _ensure_deps():
|
def _ensure_deps():
|
||||||
try:
|
try:
|
||||||
import cryptography # noqa: F401
|
import cryptography # noqa: F401
|
||||||
|
|||||||
Reference in New Issue
Block a user