This is an automated email from the ASF dual-hosted git repository.

tomsun28 pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/hertzbeat.git


The following commit(s) were added to refs/heads/master by this push:
     new e250a91b5b [bugfix] Enable TLSv1.3 on the shared HTTP client (#2106) 
(#4422)
e250a91b5b is described below

commit e250a91b5b895f31acdd1473cf20d40e0f05026e
Author: 晚安code <[email protected]>
AuthorDate: Mon Oct 5 10:03:21 2026 +0800

    [bugfix] Enable TLSv1.3 on the shared HTTP client (#2106) (#4422)
    
    Co-authored-by: Cursor <[email protected]>
    Co-authored-by: Tomsun28 <[email protected]>
---
 .../collect/common/http/CommonHttpClient.java      |  6 +++-
 .../common/http/CommonHttpClientSslTest.java       | 42 ++++++++++++++++++++++
 2 files changed, 47 insertions(+), 1 deletion(-)

diff --git 
a/hertzbeat-collector/hertzbeat-collector-common/src/main/java/org/apache/hertzbeat/collector/collect/common/http/CommonHttpClient.java
 
b/hertzbeat-collector/hertzbeat-collector-common/src/main/java/org/apache/hertzbeat/collector/collect/common/http/CommonHttpClient.java
index cda6ce8259..811f041023 100644
--- 
a/hertzbeat-collector/hertzbeat-collector-common/src/main/java/org/apache/hertzbeat/collector/collect/common/http/CommonHttpClient.java
+++ 
b/hertzbeat-collector/hertzbeat-collector-common/src/main/java/org/apache/hertzbeat/collector/collect/common/http/CommonHttpClient.java
@@ -94,7 +94,7 @@ public class CommonHttpClient {
     /**
      * ssl supported version
      */
-    private static final String[] SUPPORTED_SSL = {"TLSv1", "TLSv1.1", 
"TLSv1.2", "SSLv3"};
+    private static final String[] SUPPORTED_SSL = {"TLSv1", "TLSv1.1", 
"TLSv1.2", "TLSv1.3"};
 
     static {
         try {
@@ -174,6 +174,10 @@ public class CommonHttpClient {
         connectionManager = manager;
     }
 
+    static String[] supportedSslProtocolsForTest() {
+        return SUPPORTED_SSL.clone();
+    }
+
     static void setBeforeCleanupHookForTest(Runnable hook) {
         beforeCleanupHook = hook;
     }
diff --git 
a/hertzbeat-collector/hertzbeat-collector-common/src/test/java/org/apache/hertzbeat/collector/collect/common/http/CommonHttpClientSslTest.java
 
b/hertzbeat-collector/hertzbeat-collector-common/src/test/java/org/apache/hertzbeat/collector/collect/common/http/CommonHttpClientSslTest.java
new file mode 100644
index 0000000000..fc0bcce1da
--- /dev/null
+++ 
b/hertzbeat-collector/hertzbeat-collector-common/src/test/java/org/apache/hertzbeat/collector/collect/common/http/CommonHttpClientSslTest.java
@@ -0,0 +1,42 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one or more
+ * contributor license agreements.  See the NOTICE file distributed with
+ * this work for additional information regarding copyright ownership.
+ * The ASF licenses this file to You under the Apache License, Version 2.0
+ * (the "License"); you may not use this file except in compliance with
+ * the License.  You may obtain a copy of the License at
+ *
+ *     http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+
+package org.apache.hertzbeat.collector.collect.common.http;
+
+import static org.junit.jupiter.api.Assertions.assertArrayEquals;
+import static org.junit.jupiter.api.Assertions.assertFalse;
+import static org.junit.jupiter.api.Assertions.assertTrue;
+
+import java.util.Arrays;
+import java.util.List;
+import org.junit.jupiter.api.Test;
+
+/**
+ * Tests for CommonHttpClient TLS protocol configuration.
+ */
+class CommonHttpClientSslTest {
+
+    @Test
+    void supportedSslProtocolsIncludeTls13AndExcludeSslv3() {
+        String[] protocols = CommonHttpClient.supportedSslProtocolsForTest();
+        List<String> protocolList = Arrays.asList(protocols);
+
+        assertTrue(protocolList.contains("TLSv1.3"));
+        assertFalse(protocolList.contains("SSLv3"));
+        assertArrayEquals(new String[]{"TLSv1", "TLSv1.1", "TLSv1.2", 
"TLSv1.3"}, protocols);
+    }
+}


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to