Skip to content

Fix createHttpClient - #347

Open
jpantonow wants to merge 1 commit into
aivanovski:masterfrom
jpantonow:fix/createhttpclient-sslcontextspec-ecccf29c6686-97bf6da120
Open

jpantonow wants to merge 1 commit into
aivanovski:masterfrom
jpantonow:fix/createhttpclient-sslcontextspec-ecccf29c6686-97bf6da120

Conversation

@jpantonow

Copy link
Copy Markdown

What does this implement/fix?

Property Value
Method createHttpClient
Class com.ivanovsky.passnotes.data.repository.file.webdav.HttpClientFactory
File app/src/main/kotlin/com/ivanovsky/passnotes/data/repository/file/webdav/HttpClientFactory.kt
Specification SSLContextSpec
Analysis tool ape

Summary

Observed dynamic-analysis failure

The dynamic-analysis run by ape reported (SSLContextSpec) while exercising com.ivanovsky.passnotes.data.repository.file.webdav.HttpClientFactory.createHttpClient:

expecting one of {TLSv1.2, TLSv1.3} but found TLS.

Root cause

The DEBUG and UNSECURE branch invokes javax.net.ssl.SSLContext.getInstance("TLS"), which violates SSLContextSpec's reported constraint requiring the requested protocol argument to be exactly "TLSv1.2" or "TLSv1.3".

Correction strategy

Retain the provider-selected generic SSLContext("TLS") and filter only explicit legacy protocol names from the provider's enabled protocol set on each derived connection/socket. Do not construct a TLSv1.2/TLSv1.3 closed allowlist; retain unknown future TLS protocol names and fail closed on an empty acceptable set.

Coordinated changes

  • app/src/main/kotlin/com/ivanovsky/passnotes/data/repository/file/webdav/HttpClientFactory.kt: Preserves the generic TLS SSLContext and immediate initialization, then filters each provider-created SSL socket's already-enabled protocols. SSL variants and TLSv1/TLSv1.0/TLSv1.1 are removed, TLSv1.2/TLSv1.3 and future protocol names remain when provider-enabled, and an empty result throws before a socket can be returned. The internal helper is callable by the coordinated unit tests without reflection.
  • app/src/test/kotlin/com/ivanovsky/passnotes/data/repository/file/webdav/HttpClientFactoryTest.kt: Adds direct unit coverage for the coordinated internal helper: legacy SSL and TLS protocol names are removed, provider-enabled TLSv1.2 and TLSv1.3 remain, a future TLS name remains, and an all-legacy input throws IllegalStateException rather than permitting socket configuration.

Verification included

  • In app/src/test/kotlin/com/ivanovsky/passnotes/data/repository/file/webdav/HttpClientFactoryTest.kt, verify legacy SSL and TLSv1/TLSv1.0/TLSv1.1 protocol names are removed.
  • Verify TLSv1.2, TLSv1.3, and an unknown future TLS protocol name remain when provider-enabled.
  • Verify filtering fails closed with IllegalStateException when every enabled protocol is legacy.
  • Verify SSL protocol variants, TLSv1, TLSv1.0, and TLSv1.1 are removed from provider-enabled protocol input.
  • Verify TLSv1.2 and TLSv1.3 remain when provider-enabled.
  • Verify an unknown future TLS protocol remains enabled.
  • Verify filtering fails closed with IllegalStateException when only removed legacy protocols are supplied.

How was this tested?

  • Automated test coverage added in 1 test file(s)
  • The patched module compiles successfully (:app:compileAutomationDebugKotlin); the full multi-module build was not completed in this environment
  • Confirmed by a project maintainer

Additional context

I’m an undergraduate Computer Engineering student at the University of Brasília (UnB), and this contribution is part of a research project involving static analysis of Android apps.

I’m happy to adjust the implementation to better match the project’s architecture, coding conventions, or maintainers’ recommendations.

Signed-off-by: jpantonow <jpantonow@gmail.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant