mirror of
https://github.com/saphid/frame-control.git
synced 2026-10-06 03:00:18 +02:00
Bundle a CA list so HTTPS works from Python on fresh Windows
The bundled Python only trusts roots already in the Windows certificate store, which Windows fills lazily, so on a new install Steam store search, F-Droid downloads and the compat DB failed with CERTIFICATE_VERIFY_FAILED. fetch-deps.js now also bundles curl's pinned copy of Mozilla's CA list, and the server adds it to the default HTTPS context on top of the system certificates (before any urlopen, since urllib keeps the context it first builds). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
1 parent
1a0e54d8bd
commit
770f26c703
5 files changed
+40
-8
No files matched your search
@@ -8,6 +8,7 @@ CLI (used by the Electron app, so terminal handling lives in one place):
|
||||
import os
|
||||
import shlex
|
||||
import shutil
|
||||
import ssl
|
||||
import subprocess
|
||||
import sys
|
||||
from pathlib import Path
|
||||
@@ -108,6 +109,27 @@ def adb():
|
||||
return found
|
||||
|
||||
|
||||
def trust_bundled_cas():
|
||||
"""Trust the app's CA bundle for HTTPS as well as the system's certificates.
|
||||
|
||||
Python on Windows only sees the root certificates already in the Windows
|
||||
store, and a fresh install fetches those lazily, so Steam and F-Droid can
|
||||
fail with CERTIFICATE_VERIFY_FAILED. The app bundles curl's copy of Mozilla's
|
||||
CA list (app/build/fetch-deps.js); outside the app this does nothing. Call it
|
||||
before the first urlopen: urllib keeps the HTTPS context it builds then.
|
||||
"""
|
||||
tools = os.environ.get("FRAME_CONTROL_TOOLS")
|
||||
cafile = os.path.join(tools, "cacert.pem") if tools else None
|
||||
if not cafile or not os.path.isfile(cafile):
|
||||
return
|
||||
|
||||
def context(*args, **kwargs):
|
||||
ctx = ssl.create_default_context(*args, **kwargs)
|
||||
ctx.load_verify_locations(cafile)
|
||||
return ctx
|
||||
ssl._create_default_https_context = context # urllib's default for HTTPS
|
||||
|
||||
|
||||
def open_path(path):
|
||||
"""Show a folder or file in the file manager."""
|
||||
path = str(path)
|
||||
|
||||
Reference in new issue
Block a user