fbc788c799
Security: with --verify-hostname off (the default), the old NoVerify verifier accepted ANY server certificate — the CA loaded from --tls-ca was never consulted, so the documented pinning was a no-op and the connection was trivially MITM-able. Replace it with PinnedCertVerifier: the presented end-entity cert must be byte-identical to a cert in the --tls-ca file (any cert in a multi-cert PEM matches, supporting rotation). Signature validation now uses the ring provider's full algorithm set instead of a hardcoded 3-scheme list. Empty PEM files fail fast instead of failing closed per-handshake. The --verify-hostname path is unchanged (WebPki root-store validation). Also: the third argument of connect_async_tls_with_config is tungstenite's disable_nagle flag, not a verification toggle — we were passing verify_hostname there, leaving Nagle ON for default users. Pass true unconditionally, and disable Nagle on the plain ws:// path too; socktop exchanges small request/response frames where Nagle only adds latency. Client now consumes the connector via a dual path+version dep so these fixes are in local builds and CI before the crates.io publish (cargo strips the path on publish). Connector version -> 1.51.0. Verified E2E: agent A's cert connects to agent A; agent B's cert against agent A fails the handshake (the rpi-worker-1 wrong-PEM scenario); --verify-hostname against a 127.0.0.1 SAN still connects. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
61 lines
1.9 KiB
TOML
61 lines
1.9 KiB
TOML
[package]
|
|
name = "socktop_connector"
|
|
version = "1.51.0"
|
|
edition = "2024"
|
|
license = "MIT"
|
|
description = "WebSocket connector library for socktop agent communication"
|
|
authors = ["Jason Witty <jasonpwitty+socktop@proton.me>"]
|
|
repository = "https://github.com/jasonwitty/socktop"
|
|
readme = "README.md"
|
|
keywords = ["monitoring", "websocket", "metrics", "system"]
|
|
categories = ["network-programming", "development-tools"]
|
|
documentation = "https://docs.rs/socktop_connector"
|
|
|
|
[lib]
|
|
crate-type = ["cdylib", "rlib"]
|
|
|
|
# docs.rs specific metadata
|
|
[package.metadata.docs.rs]
|
|
all-features = true
|
|
rustdoc-args = ["--cfg", "docsrs"]
|
|
|
|
[dependencies]
|
|
# WebSocket client - only for non-WASM targets
|
|
tokio-tungstenite = { workspace = true, optional = true }
|
|
tokio = { workspace = true, optional = true }
|
|
futures-util = { workspace = true, optional = true }
|
|
url = { workspace = true, optional = true }
|
|
|
|
# WASM WebSocket support
|
|
wasm-bindgen = { version = "0.2", optional = true }
|
|
wasm-bindgen-futures = { version = "0.4", optional = true }
|
|
js-sys = { version = "0.3", optional = true }
|
|
web-sys = { version = "0.3", features = ["WebSocket", "MessageEvent", "ErrorEvent", "CloseEvent", "BinaryType", "Window", "console"], optional = true }
|
|
|
|
# TLS support
|
|
rustls = { version = "0.23", features = ["ring"], optional = true }
|
|
rustls-pemfile = { version = "2.1", optional = true }
|
|
|
|
# Serialization - always available
|
|
serde = { workspace = true }
|
|
serde_json = { workspace = true }
|
|
|
|
# Compression - used in both networking and WASM modes
|
|
flate2 = "1.0"
|
|
|
|
# Protobuf - always available
|
|
prost = { workspace = true }
|
|
|
|
# Error handling - always available
|
|
thiserror = "2.0"
|
|
|
|
[build-dependencies]
|
|
prost-build = "0.13"
|
|
protoc-bin-vendored = "3.0"
|
|
|
|
[features]
|
|
default = ["networking", "tls"]
|
|
networking = ["tokio-tungstenite", "tokio", "futures-util", "url"]
|
|
tls = ["networking", "rustls", "rustls-pemfile"]
|
|
wasm = ["wasm-bindgen", "wasm-bindgen-futures", "js-sys", "web-sys"] # WASM-compatible networking with compression
|