device infos
This commit is contained in:
@@ -1,10 +1,36 @@
|
||||
import 'dart:io';
|
||||
|
||||
/// ─────────────────────────────────────────────────────────────────────────
|
||||
/// THE APP VALIDATES CERTIFICATES AGAIN
|
||||
///
|
||||
/// This class used to override `badCertificateCallback` to return `true` for
|
||||
/// every certificate, on every host, and it was installed globally in three
|
||||
/// places — `main`, the background isolate and the notification handler. That
|
||||
/// is not a lenient setting; it is **TLS switched off**. Any network the rider's
|
||||
/// phone joins could present a self-signed certificate for `api.doormile.com`
|
||||
/// and the app would hand over his session token, his live position and the
|
||||
/// day's cash figures without a word.
|
||||
///
|
||||
/// It is the kind of thing that gets added once to get past a staging server
|
||||
/// and then ships. Both live hosts were checked before removing it and both
|
||||
/// present valid, publicly-trusted certificates — `api.doormile.com` and
|
||||
/// `queue.workolik.com` verify strictly under TLS 1.3 against Let's Encrypt.
|
||||
/// Nothing needed the bypass.
|
||||
///
|
||||
/// ── What is left, and why the class is still here ──
|
||||
///
|
||||
/// Dart's default `HttpClient` already validates properly, so the honest
|
||||
/// version of this override is one that changes nothing about trust. It stays
|
||||
/// as a named place to put a real connection policy — a timeout, a proxy, a
|
||||
/// pinned certificate — so that the next person who needs one has somewhere
|
||||
/// obvious to put it that is not "turn the checks off".
|
||||
///
|
||||
/// **Never restore the callback.** If a host genuinely cannot present a valid
|
||||
/// certificate, pin *that host's* certificate here; do not trust every host on
|
||||
/// the internet to work around one.
|
||||
/// ─────────────────────────────────────────────────────────────────────────
|
||||
class MyHttpOverrides extends HttpOverrides {
|
||||
@override
|
||||
HttpClient createHttpClient(SecurityContext? context) {
|
||||
return super.createHttpClient(context)
|
||||
..badCertificateCallback =
|
||||
(X509Certificate cert, String host, int port) => true;
|
||||
}
|
||||
HttpClient createHttpClient(SecurityContext? context) =>
|
||||
super.createHttpClient(context);
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user