mirror of
https://github.com/9001/copyparty.git
synced 2026-10-05 22:04:38 +01:00
certs: conditional whining
This commit is contained in:
@@ -39,6 +39,7 @@ from .__init__ import (
|
|||||||
from .__version__ import CODENAME, S_BUILD_DT, S_VERSION
|
from .__version__ import CODENAME, S_BUILD_DT, S_VERSION
|
||||||
from .authsrv import expand_config_file, split_cfg_ln, upgrade_cfg_fmt
|
from .authsrv import expand_config_file, split_cfg_ln, upgrade_cfg_fmt
|
||||||
from .bos import bos
|
from .bos import bos
|
||||||
|
from .cert import NO_TLS
|
||||||
from .cfg import flagcats, onedash
|
from .cfg import flagcats, onedash
|
||||||
from .mdns import DNS_VND
|
from .mdns import DNS_VND
|
||||||
from .qrkode import VENDORED as QR_VND
|
from .qrkode import VENDORED as QR_VND
|
||||||
@@ -100,11 +101,12 @@ if PY2:
|
|||||||
range = xrange # type: ignore
|
range = xrange # type: ignore
|
||||||
|
|
||||||
try:
|
try:
|
||||||
if os.environ.get("PRTY_NO_TLS"):
|
if NO_TLS:
|
||||||
raise Exception()
|
raise Exception()
|
||||||
|
|
||||||
HAVE_SSL = True
|
|
||||||
import ssl
|
import ssl
|
||||||
|
|
||||||
|
HAVE_SSL = True
|
||||||
except:
|
except:
|
||||||
HAVE_SSL = False
|
HAVE_SSL = False
|
||||||
|
|
||||||
@@ -2491,7 +2493,8 @@ def main(argv: Optional[list[str]] = None) -> None:
|
|||||||
if al.ciphers:
|
if al.ciphers:
|
||||||
configure_ssl_ciphers(al)
|
configure_ssl_ciphers(al)
|
||||||
else:
|
else:
|
||||||
warn("ssl module does not exist; cannot enable https")
|
if not al.http_only and not NO_TLS:
|
||||||
|
warn("ssl module does not exist; cannot enable https")
|
||||||
al.http_only = True
|
al.http_only = True
|
||||||
|
|
||||||
if PY2 and WINDOWS and al.e2d:
|
if PY2 and WINDOWS and al.e2d:
|
||||||
|
|||||||
+5
-3
@@ -8,6 +8,7 @@ import time
|
|||||||
from .__init__ import ANYWIN
|
from .__init__ import ANYWIN
|
||||||
from .util import Netdev, atomic_move, load_resource, runcmd, wunlink
|
from .util import Netdev, atomic_move, load_resource, runcmd, wunlink
|
||||||
|
|
||||||
|
NO_TLS = bool(os.environ.get("PRTY_NO_TLS"))
|
||||||
HAVE_CFSSL = not os.environ.get("PRTY_NO_CFSSL")
|
HAVE_CFSSL = not os.environ.get("PRTY_NO_CFSSL")
|
||||||
|
|
||||||
if True: # pylint: disable=using-constant-test
|
if True: # pylint: disable=using-constant-test
|
||||||
@@ -70,8 +71,9 @@ def ensure_cert(log: "RootLogger", args) -> None:
|
|||||||
with open(args.cert, "rb") as f:
|
with open(args.cert, "rb") as f:
|
||||||
active_cert = f.read()
|
active_cert = f.read()
|
||||||
if active_cert == cert_insec:
|
if active_cert == cert_insec:
|
||||||
t = "using default TLS certificate; https will be insecure:\033[36m {}"
|
t = "using default TLS certificate; %s will be insecure:\033[36m %s"
|
||||||
log("cert", t.format(args.cert), 3)
|
t2 = "https" if not args.ftps else "ftps"
|
||||||
|
log("cert", t % (t2, args.cert), 3)
|
||||||
except:
|
except:
|
||||||
pass
|
pass
|
||||||
|
|
||||||
@@ -252,7 +254,7 @@ def _gen_srv(log: "RootLogger", args, netdevs: dict[str, Netdev]):
|
|||||||
def gencert(log: "RootLogger", args, netdevs: dict[str, Netdev]):
|
def gencert(log: "RootLogger", args, netdevs: dict[str, Netdev]):
|
||||||
global HAVE_CFSSL
|
global HAVE_CFSSL
|
||||||
|
|
||||||
if args.http_only:
|
if args.http_only and not args.ftps:
|
||||||
return
|
return
|
||||||
|
|
||||||
if args.no_crt or args.certkey or not HAVE_CFSSL:
|
if args.no_crt or args.certkey or not HAVE_CFSSL:
|
||||||
|
|||||||
+11
-9
@@ -8,22 +8,24 @@ import socket
|
|||||||
import threading # typechk
|
import threading # typechk
|
||||||
import time
|
import time
|
||||||
|
|
||||||
try:
|
|
||||||
if os.environ.get("PRTY_NO_TLS"):
|
|
||||||
raise Exception()
|
|
||||||
|
|
||||||
HAVE_SSL = True
|
|
||||||
import ssl
|
|
||||||
except:
|
|
||||||
HAVE_SSL = False
|
|
||||||
|
|
||||||
from . import util as Util
|
from . import util as Util
|
||||||
from .__init__ import TYPE_CHECKING, EnvParams
|
from .__init__ import TYPE_CHECKING, EnvParams
|
||||||
from .authsrv import AuthSrv # typechk
|
from .authsrv import AuthSrv # typechk
|
||||||
|
from .cert import NO_TLS
|
||||||
from .httpcli import HttpCli
|
from .httpcli import HttpCli
|
||||||
from .u2idx import U2idx
|
from .u2idx import U2idx
|
||||||
from .util import HMaccas, NetMap, min_ex, shut_socket
|
from .util import HMaccas, NetMap, min_ex, shut_socket
|
||||||
|
|
||||||
|
try:
|
||||||
|
if NO_TLS:
|
||||||
|
raise Exception()
|
||||||
|
|
||||||
|
import ssl
|
||||||
|
|
||||||
|
HAVE_SSL = True
|
||||||
|
except:
|
||||||
|
HAVE_SSL = False
|
||||||
|
|
||||||
if True: # pylint: disable=using-constant-test
|
if True: # pylint: disable=using-constant-test
|
||||||
from typing import Optional, Pattern, Union
|
from typing import Optional, Pattern, Union
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user