fix(bitwarden): add SSL context for API requests and set device identifiers

This commit is contained in:
2026-08-26 12:53:10 +02:00
parent 0055397ed5
commit d53c7fc85c
2 changed files with 22 additions and 4 deletions
+16 -4
View File
@@ -3,6 +3,8 @@ Bitwarden/Vaultwarden REST API client.
Handles authentication, vault sync, and API communication.
"""
import json
import os
import ssl
from base64 import b64decode, b64encode
from typing import Optional, Tuple
@@ -11,6 +13,15 @@ import aiohttp
from crypto import BitwardenCrypto, PinCrypto
def _get_ssl_context():
ssl_ctx = ssl.create_default_context()
for ca_path in ["/etc/ssl/certs/ca-certificates.crt", "/etc/ssl/certs/ca-bundle.crt"]:
if os.path.exists(ca_path):
ssl_ctx.load_verify_locations(ca_path)
break
return ssl_ctx
# Default URLs
BITWARDEN_API_BASE = "https://api.bitwarden.com"
BITWARDEN_IDENTITY_BASE = "https://identity.bitwarden.com"
@@ -91,7 +102,7 @@ class BitwardenClient:
async with aiohttp.ClientSession() as session:
async with session.request(
method, url, headers=headers, json=data, params=params
method, url, headers=headers, json=data, params=params, ssl=_get_ssl_context()
) as resp:
text = await resp.text()
if resp.status >= 400:
@@ -157,8 +168,9 @@ class BitwardenClient:
"username": email,
"password": master_password_hash,
"scope": "api offline_access",
"client_id": "connector",
"client_id": "web",
"deviceType": DEVICE_TYPE,
"deviceIdentifier": "decky-vaultwarden",
"deviceName": "decky-vaultwarden",
}
@@ -173,7 +185,7 @@ class BitwardenClient:
# Use form data instead of JSON
async with aiohttp.ClientSession() as session:
async with session.post(
url, data=data, headers=headers
url, data=data, headers=headers, ssl=_get_ssl_context()
) as resp:
text = await resp.text()
if resp.status >= 400:
@@ -225,7 +237,7 @@ class BitwardenClient:
async with aiohttp.ClientSession() as session:
async with session.post(
url, data=data, headers=headers
url, data=data, headers=headers, ssl=_get_ssl_context()
) as resp:
text = await resp.text()
if resp.status >= 400:
+6
View File
@@ -15,6 +15,12 @@ py_modules_dir = os.path.join(plugin_dir, "py_modules")
sys.path.insert(0, py_modules_dir)
sys.path.insert(0, plugin_dir)
if "SSL_CERT_FILE" not in os.environ:
for ca_path in ["/etc/ssl/certs/ca-certificates.crt", "/etc/ssl/certs/ca-bundle.crt"]:
if os.path.exists(ca_path):
os.environ["SSL_CERT_FILE"] = ca_path
break
def _ensure_deps():
try:
import cryptography # noqa: F401