Repository navigation
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (8)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe CLI adds local PEM-chain validation when ChangesLocal chain validation
Priority: ➖ Normal Estimated code review effort: 4 (Complex) | ~45 minutes Change: Feature Sequence Diagram(s)sequenceDiagram
participant CLI
participant Verifier as validation::Verifier
participant ValidationReport as validation::Report
participant OutputReport as report::Report
CLI->>Verifier: Build verifier from configured roots
CLI->>ValidationReport: Check certificate chain and hostname
CLI->>OutputReport: Include optional validation results
Merge Risk: ⚪ Minimal · up to This adds local certificate-chain validation reporting for PEM files and stdin, and existing exit-code behavior is unchanged. No concrete merge-blocking risk was identified from the supplied evidence. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 48.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 50 functions across 5 files. (3 skipped: 3 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Reproducible examples for Build this PR: gh pr checkout 544
cargo build --locked
ICC="$PWD/target/debug/inspect-cert-chain"Save the public chain with curl. These commands were run with curl 8.7.1; use a build that supports curl --fail --silent --show-error --max-time 30 \
--output /dev/null --write-out '%{certs}' https://example.com \
| sed -n '/-----BEGIN CERTIFICATE-----/,/-----END CERTIFICATE-----/p' \
> example-chain.pemCheck the expected hostname: "$ICC" --file example-chain.pem --check --hostname example.com --fields subjectValidation excerpt from the captured output: Check the same chain against a different hostname: "$ICC" --file example-chain.pem --check --hostname wrong.example --fields subjectBoth commands returned exit code |
Local PEM chains can be inspected and checked for expiry, but their trust and hostname are not checked. Add
--check --hostnamefor files and stdin, with system roots and repeatable--ca-fileinputs.Check certificate signatures, validity dates, hostname, CA signing usage, path length, name constraints, and critical extensions. Report results in text and JSON. Keep the existing date-based exit codes and field selection. Revocation is explicitly reported as not checked.
This is layer 1 of 4. Remote validation, supplied CRLs, and CRL downloads follow in separate PRs.
Validation on macOS:
just test(72 passed) andnix develop -c just check(formatting and Clippy passed).Summary by CodeRabbit
--check --hostname, supporting PEM input from files or stdin.--ca-fileoptions add custom roots.