fix(bitwarden): add SSL context for API requests and set device identifiers

This commit is contained in:
2026-08-26 12:53:10 +02:00
parent 0055397ed5
commit d53c7fc85c
2 changed files with 22 additions and 4 deletions
+16 -4
View File
@@ -3,6 +3,8 @@ Bitwarden/Vaultwarden REST API client.
Handles authentication, vault sync, and API communication. Handles authentication, vault sync, and API communication.
""" """
import json import json
import os
import ssl
from base64 import b64decode, b64encode from base64 import b64decode, b64encode
from typing import Optional, Tuple from typing import Optional, Tuple
@@ -11,6 +13,15 @@ import aiohttp
from crypto import BitwardenCrypto, PinCrypto from crypto import BitwardenCrypto, PinCrypto
def _get_ssl_context():
ssl_ctx = ssl.create_default_context()
for ca_path in ["/etc/ssl/certs/ca-certificates.crt", "/etc/ssl/certs/ca-bundle.crt"]:
if os.path.exists(ca_path):
ssl_ctx.load_verify_locations(ca_path)
break
return ssl_ctx
# Default URLs # Default URLs
BITWARDEN_API_BASE = "https://api.bitwarden.com" BITWARDEN_API_BASE = "https://api.bitwarden.com"
BITWARDEN_IDENTITY_BASE = "https://identity.bitwarden.com" BITWARDEN_IDENTITY_BASE = "https://identity.bitwarden.com"
@@ -91,7 +102,7 @@ class BitwardenClient:
async with aiohttp.ClientSession() as session: async with aiohttp.ClientSession() as session:
async with session.request( async with session.request(
method, url, headers=headers, json=data, params=params method, url, headers=headers, json=data, params=params, ssl=_get_ssl_context()
) as resp: ) as resp:
text = await resp.text() text = await resp.text()
if resp.status >= 400: if resp.status >= 400:
@@ -157,8 +168,9 @@ class BitwardenClient:
"username": email, "username": email,
"password": master_password_hash, "password": master_password_hash,
"scope": "api offline_access", "scope": "api offline_access",
"client_id": "connector", "client_id": "web",
"deviceType": DEVICE_TYPE, "deviceType": DEVICE_TYPE,
"deviceIdentifier": "decky-vaultwarden",
"deviceName": "decky-vaultwarden", "deviceName": "decky-vaultwarden",
} }
@@ -173,7 +185,7 @@ class BitwardenClient:
# Use form data instead of JSON # Use form data instead of JSON
async with aiohttp.ClientSession() as session: async with aiohttp.ClientSession() as session:
async with session.post( async with session.post(
url, data=data, headers=headers url, data=data, headers=headers, ssl=_get_ssl_context()
) as resp: ) as resp:
text = await resp.text() text = await resp.text()
if resp.status >= 400: if resp.status >= 400:
@@ -225,7 +237,7 @@ class BitwardenClient:
async with aiohttp.ClientSession() as session: async with aiohttp.ClientSession() as session:
async with session.post( async with session.post(
url, data=data, headers=headers url, data=data, headers=headers, ssl=_get_ssl_context()
) as resp: ) as resp:
text = await resp.text() text = await resp.text()
if resp.status >= 400: if resp.status >= 400:
+6
View File
@@ -15,6 +15,12 @@ py_modules_dir = os.path.join(plugin_dir, "py_modules")
sys.path.insert(0, py_modules_dir) sys.path.insert(0, py_modules_dir)
sys.path.insert(0, plugin_dir) sys.path.insert(0, plugin_dir)
if "SSL_CERT_FILE" not in os.environ:
for ca_path in ["/etc/ssl/certs/ca-certificates.crt", "/etc/ssl/certs/ca-bundle.crt"]:
if os.path.exists(ca_path):
os.environ["SSL_CERT_FILE"] = ca_path
break
def _ensure_deps(): def _ensure_deps():
try: try:
import cryptography # noqa: F401 import cryptography # noqa: F401