feat: add ca option for schema registry #17826
Closed
Task list completed / task-list-completed
Started
2024-10-17 09:06:22
ago
2 / 8 tasks completed
6 tasks still to be completed
Details
Required Tasks
Task | Status |
---|---|
I have written necessary rustdoc comments | Incomplete |
I have added necessary unit tests and integration tests | Incomplete |
I have added test labels as necessary. See details. | Incomplete |
I have added fuzzing tests or opened an issue to track them. (Optional, recommended for new SQL features #7934). | Incomplete |
My PR contains breaking changes. (If it deprecates some features, please create a tracking issue to remove them in the future). | Incomplete |
All checks passed in ./risedev check (or alias, ./risedev c ) |
Completed |
My PR contains critical fixes that are necessary to be merged into the latest release. (Please check out the details) | Incomplete |
My PR needs documentation updates. (Please use the Release note section below to summarize the impact on users) | Completed |
if schema.registry.ca set to ignore : (danger) You should think very carefully before using this method. If invalid certificates are trusted, any certificate for any site will be trusted for use. This includes expired certificates. This introduces significant vulnerabilities, and should only be used as a last resort. (from https://docs.rs/reqwest/latest/reqwest/struct.ClientBuilder.html#method.danger_accept_invalid_certs) |
Incomplete |
otherwise, add a custom root certificate (from https://docs.rs/reqwest/latest/reqwest/struct.ClientBuilder.html#method.add_root_certificate) | Incomplete |
Understand the implications of revoking this secret by investigating where it is used in your code. | Incomplete |
Replace and store your secrets safely. Learn here the best practices. | Incomplete |
Revoke and rotate these secrets. | Incomplete |
If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data. | Incomplete |
following these best practices for managing and storing secrets including API keys and other credentials | Incomplete |
install secret detection on pre-commit to catch secret before it leaves your machine and ease remediation. | Incomplete |
Client::new returns ClientBuildError rather than InvalidOptionError |
Incomplete |
callers of Client::new may eventually transform ClientBuildError into a new variant of SchemaFetchError |
Incomplete |
Loading