Skip to content

fix: verify HTTP agent TLS certificates by default - #237

Open
cenab wants to merge 1 commit into
THUDM:mainfrom
cenab:fix/http-agent-tls
Open

cenab wants to merge 1 commit into
THUDM:mainfrom
cenab:fix/http-agent-tls

Conversation

@cenab

@cenab cenab commented Sep 28, 2026

Copy link
Copy Markdown

HTTPAgent currently disables certificate verification for every inference call by
temporarily replacing requests.Session.merge_environment_settings process-wide.
This also changes unrelated sessions while the request is in flight.

This change uses Requests’ normal certificate verification by default and passes
the optional verify value directly to this agent’s request. A CA bundle path
supports private certificate authorities. Existing self-signed deployments can
explicitly select verify: false; that choice remains scoped to the agent’s
request and retains Requests’ warning. The config documentation explains this
migration.

Validation on d1e4a10db08c87075c78972e48ecc182be03e2d5:

  • python -m unittest discover -s tests -v: 3 passed. A temporary local HTTPS
    server verifies default rejection of an untrusted certificate, acceptance of an
    explicit CA bundle, and isolation of an explicit opt-out from other sessions.
  • Before the fix, the default-rejection regression test fails because the
    untrusted request succeeds.
  • python scripts/validate_lite_configs.py: passed, matching repository CI.
  • The actual ConfigLoader and InstanceFactory path was also exercised against
    controlled local HTTP responses.

The tests generate and remove their own short-lived certificate and key. No
hosted model or full benchmark result is claimed. OpenAI Codex assisted with this
change and validation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant