From 80cf7bfdc0d76baf9ac392564d785088e984bea0 Mon Sep 17 00:00:00 2001 From: ed Date: Tue, 1 Sep 2026 23:00:10 +0200 Subject: [PATCH] certs: conditional whining --- copyparty/__main__.py | 9 ++++++--- copyparty/cert.py | 8 +++++--- copyparty/httpconn.py | 20 +++++++++++--------- 3 files changed, 22 insertions(+), 15 deletions(-) diff --git a/copyparty/__main__.py b/copyparty/__main__.py index 63155d8bc..aeee2591e 100644 --- a/copyparty/__main__.py +++ b/copyparty/__main__.py @@ -39,6 +39,7 @@ from .__init__ import ( from .__version__ import CODENAME, S_BUILD_DT, S_VERSION from .authsrv import expand_config_file, split_cfg_ln, upgrade_cfg_fmt from .bos import bos +from .cert import NO_TLS from .cfg import flagcats, onedash from .mdns import DNS_VND from .qrkode import VENDORED as QR_VND @@ -100,11 +101,12 @@ if PY2: range = xrange # type: ignore try: - if os.environ.get("PRTY_NO_TLS"): + if NO_TLS: raise Exception() - HAVE_SSL = True import ssl + + HAVE_SSL = True except: HAVE_SSL = False @@ -2491,7 +2493,8 @@ def main(argv: Optional[list[str]] = None) -> None: if al.ciphers: configure_ssl_ciphers(al) else: - warn("ssl module does not exist; cannot enable https") + if not al.http_only and not NO_TLS: + warn("ssl module does not exist; cannot enable https") al.http_only = True if PY2 and WINDOWS and al.e2d: diff --git a/copyparty/cert.py b/copyparty/cert.py index 54c523a90..82e495381 100644 --- a/copyparty/cert.py +++ b/copyparty/cert.py @@ -8,6 +8,7 @@ import time from .__init__ import ANYWIN from .util import Netdev, atomic_move, load_resource, runcmd, wunlink +NO_TLS = bool(os.environ.get("PRTY_NO_TLS")) HAVE_CFSSL = not os.environ.get("PRTY_NO_CFSSL") if True: # pylint: disable=using-constant-test @@ -70,8 +71,9 @@ def ensure_cert(log: "RootLogger", args) -> None: with open(args.cert, "rb") as f: active_cert = f.read() if active_cert == cert_insec: - t = "using default TLS certificate; https will be insecure:\033[36m {}" - log("cert", t.format(args.cert), 3) + t = "using default TLS certificate; %s will be insecure:\033[36m %s" + t2 = "https" if not args.ftps else "ftps" + log("cert", t % (t2, args.cert), 3) except: pass @@ -252,7 +254,7 @@ def _gen_srv(log: "RootLogger", args, netdevs: dict[str, Netdev]): def gencert(log: "RootLogger", args, netdevs: dict[str, Netdev]): global HAVE_CFSSL - if args.http_only: + if args.http_only and not args.ftps: return if args.no_crt or args.certkey or not HAVE_CFSSL: diff --git a/copyparty/httpconn.py b/copyparty/httpconn.py index c43a891a6..0dddbdb4c 100644 --- a/copyparty/httpconn.py +++ b/copyparty/httpconn.py @@ -8,22 +8,24 @@ import socket import threading # typechk import time -try: - if os.environ.get("PRTY_NO_TLS"): - raise Exception() - - HAVE_SSL = True - import ssl -except: - HAVE_SSL = False - from . import util as Util from .__init__ import TYPE_CHECKING, EnvParams from .authsrv import AuthSrv # typechk +from .cert import NO_TLS from .httpcli import HttpCli from .u2idx import U2idx from .util import HMaccas, NetMap, min_ex, shut_socket +try: + if NO_TLS: + raise Exception() + + import ssl + + HAVE_SSL = True +except: + HAVE_SSL = False + if True: # pylint: disable=using-constant-test from typing import Optional, Pattern, Union