This is an automated email from the ASF dual-hosted git repository.
tomsun28 pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/hertzbeat.git
The following commit(s) were added to refs/heads/master by this push:
new e250a91b5b [bugfix] Enable TLSv1.3 on the shared HTTP client (#2106)
(#4422)
e250a91b5b is described below
commit e250a91b5b895f31acdd1473cf20d40e0f05026e
Author: 晚安code <[email protected]>
AuthorDate: Mon Oct 5 10:03:21 2026 +0800
[bugfix] Enable TLSv1.3 on the shared HTTP client (#2106) (#4422)
Co-authored-by: Cursor <[email protected]>
Co-authored-by: Tomsun28 <[email protected]>
---
.../collect/common/http/CommonHttpClient.java | 6 +++-
.../common/http/CommonHttpClientSslTest.java | 42 ++++++++++++++++++++++
2 files changed, 47 insertions(+), 1 deletion(-)
diff --git
a/hertzbeat-collector/hertzbeat-collector-common/src/main/java/org/apache/hertzbeat/collector/collect/common/http/CommonHttpClient.java
b/hertzbeat-collector/hertzbeat-collector-common/src/main/java/org/apache/hertzbeat/collector/collect/common/http/CommonHttpClient.java
index cda6ce8259..811f041023 100644
---
a/hertzbeat-collector/hertzbeat-collector-common/src/main/java/org/apache/hertzbeat/collector/collect/common/http/CommonHttpClient.java
+++
b/hertzbeat-collector/hertzbeat-collector-common/src/main/java/org/apache/hertzbeat/collector/collect/common/http/CommonHttpClient.java
@@ -94,7 +94,7 @@ public class CommonHttpClient {
/**
* ssl supported version
*/
- private static final String[] SUPPORTED_SSL = {"TLSv1", "TLSv1.1",
"TLSv1.2", "SSLv3"};
+ private static final String[] SUPPORTED_SSL = {"TLSv1", "TLSv1.1",
"TLSv1.2", "TLSv1.3"};
static {
try {
@@ -174,6 +174,10 @@ public class CommonHttpClient {
connectionManager = manager;
}
+ static String[] supportedSslProtocolsForTest() {
+ return SUPPORTED_SSL.clone();
+ }
+
static void setBeforeCleanupHookForTest(Runnable hook) {
beforeCleanupHook = hook;
}
diff --git
a/hertzbeat-collector/hertzbeat-collector-common/src/test/java/org/apache/hertzbeat/collector/collect/common/http/CommonHttpClientSslTest.java
b/hertzbeat-collector/hertzbeat-collector-common/src/test/java/org/apache/hertzbeat/collector/collect/common/http/CommonHttpClientSslTest.java
new file mode 100644
index 0000000000..fc0bcce1da
--- /dev/null
+++
b/hertzbeat-collector/hertzbeat-collector-common/src/test/java/org/apache/hertzbeat/collector/collect/common/http/CommonHttpClientSslTest.java
@@ -0,0 +1,42 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one or more
+ * contributor license agreements. See the NOTICE file distributed with
+ * this work for additional information regarding copyright ownership.
+ * The ASF licenses this file to You under the Apache License, Version 2.0
+ * (the "License"); you may not use this file except in compliance with
+ * the License. You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+
+package org.apache.hertzbeat.collector.collect.common.http;
+
+import static org.junit.jupiter.api.Assertions.assertArrayEquals;
+import static org.junit.jupiter.api.Assertions.assertFalse;
+import static org.junit.jupiter.api.Assertions.assertTrue;
+
+import java.util.Arrays;
+import java.util.List;
+import org.junit.jupiter.api.Test;
+
+/**
+ * Tests for CommonHttpClient TLS protocol configuration.
+ */
+class CommonHttpClientSslTest {
+
+ @Test
+ void supportedSslProtocolsIncludeTls13AndExcludeSslv3() {
+ String[] protocols = CommonHttpClient.supportedSslProtocolsForTest();
+ List<String> protocolList = Arrays.asList(protocols);
+
+ assertTrue(protocolList.contains("TLSv1.3"));
+ assertFalse(protocolList.contains("SSLv3"));
+ assertArrayEquals(new String[]{"TLSv1", "TLSv1.1", "TLSv1.2",
"TLSv1.3"}, protocols);
+ }
+}
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]