fix(bitwarden): add SSL context for API requests and set device identifiers
This commit is contained in:
+16
-4
@@ -3,6 +3,8 @@ Bitwarden/Vaultwarden REST API client.
|
||||
Handles authentication, vault sync, and API communication.
|
||||
"""
|
||||
import json
|
||||
import os
|
||||
import ssl
|
||||
from base64 import b64decode, b64encode
|
||||
from typing import Optional, Tuple
|
||||
|
||||
@@ -11,6 +13,15 @@ import aiohttp
|
||||
from crypto import BitwardenCrypto, PinCrypto
|
||||
|
||||
|
||||
def _get_ssl_context():
|
||||
ssl_ctx = ssl.create_default_context()
|
||||
for ca_path in ["/etc/ssl/certs/ca-certificates.crt", "/etc/ssl/certs/ca-bundle.crt"]:
|
||||
if os.path.exists(ca_path):
|
||||
ssl_ctx.load_verify_locations(ca_path)
|
||||
break
|
||||
return ssl_ctx
|
||||
|
||||
|
||||
# Default URLs
|
||||
BITWARDEN_API_BASE = "https://api.bitwarden.com"
|
||||
BITWARDEN_IDENTITY_BASE = "https://identity.bitwarden.com"
|
||||
@@ -91,7 +102,7 @@ class BitwardenClient:
|
||||
|
||||
async with aiohttp.ClientSession() as session:
|
||||
async with session.request(
|
||||
method, url, headers=headers, json=data, params=params
|
||||
method, url, headers=headers, json=data, params=params, ssl=_get_ssl_context()
|
||||
) as resp:
|
||||
text = await resp.text()
|
||||
if resp.status >= 400:
|
||||
@@ -157,8 +168,9 @@ class BitwardenClient:
|
||||
"username": email,
|
||||
"password": master_password_hash,
|
||||
"scope": "api offline_access",
|
||||
"client_id": "connector",
|
||||
"client_id": "web",
|
||||
"deviceType": DEVICE_TYPE,
|
||||
"deviceIdentifier": "decky-vaultwarden",
|
||||
"deviceName": "decky-vaultwarden",
|
||||
}
|
||||
|
||||
@@ -173,7 +185,7 @@ class BitwardenClient:
|
||||
# Use form data instead of JSON
|
||||
async with aiohttp.ClientSession() as session:
|
||||
async with session.post(
|
||||
url, data=data, headers=headers
|
||||
url, data=data, headers=headers, ssl=_get_ssl_context()
|
||||
) as resp:
|
||||
text = await resp.text()
|
||||
if resp.status >= 400:
|
||||
@@ -225,7 +237,7 @@ class BitwardenClient:
|
||||
|
||||
async with aiohttp.ClientSession() as session:
|
||||
async with session.post(
|
||||
url, data=data, headers=headers
|
||||
url, data=data, headers=headers, ssl=_get_ssl_context()
|
||||
) as resp:
|
||||
text = await resp.text()
|
||||
if resp.status >= 400:
|
||||
|
||||
@@ -15,6 +15,12 @@ py_modules_dir = os.path.join(plugin_dir, "py_modules")
|
||||
sys.path.insert(0, py_modules_dir)
|
||||
sys.path.insert(0, plugin_dir)
|
||||
|
||||
if "SSL_CERT_FILE" not in os.environ:
|
||||
for ca_path in ["/etc/ssl/certs/ca-certificates.crt", "/etc/ssl/certs/ca-bundle.crt"]:
|
||||
if os.path.exists(ca_path):
|
||||
os.environ["SSL_CERT_FILE"] = ca_path
|
||||
break
|
||||
|
||||
def _ensure_deps():
|
||||
try:
|
||||
import cryptography # noqa: F401
|
||||
|
||||
Reference in New Issue
Block a user