Skip to content

feat: support tls - #948

Open
NguyenHoangSon96 wants to merge 2 commits into
masterfrom
feat/support-tls
Open

NguyenHoangSon96 wants to merge 2 commits into
masterfrom
feat/support-tls

Conversation

@NguyenHoangSon96

@NguyenHoangSon96 NguyenHoangSon96 commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Closes #947

Proposed Changes

  • Add support for config TLS/mTLS options.
  • Current support is only .cert, .crt, .key files or .p12, pfx, files.
  • Users can choose to use a single file with both cert and key in it or separate them out into two different files .crt/.cert and .key files.

Checklist

  • CHANGELOG.md updated
  • Rebased/mergeable
  • A test has been added if appropriate
  • mvn test completes successfully
  • Commit messages are conventional
  • Sign CLA (if not already signed)

@codecov-commenter

codecov-commenter commented Sep 29, 2026 •

Copy link
Copy Markdown

⚠️ Please install the 'codecov app svg image' to ensure uploads and comments are reliably processed by Codecov.

Codecov Report

❌ Patch coverage is 36.60714% with 71 lines in your changes missing coverage. Please review.
✅ Project coverage is 87.92%. Comparing base (fe48dfe) to head (2e5c9c0).

Files with missing lines Patch % Lines
...ils/src/main/java/com/influxdb/utils/TlsUtils.java 0.00% 68 Missing ⚠️
...ava/com/influxdb/client/InfluxDBClientOptions.java 93.18% 1 Missing and 2 partials ⚠️
❗ Your organization needs to install the Codecov GitHub app to enable full functionality.
Additional details and impacted files
@@             Coverage Diff              @@
##             master     #948      +/-   ##
============================================
- Coverage     88.71%   87.92%   -0.79%     
- Complexity      735      736       +1     
============================================
  Files           174      175       +1     
  Lines          7285     7397     +112     
  Branches        422      437      +15     
============================================
+ Hits           6463     6504      +41     
- Misses          688      757      +69     
- Partials        134      136       +2     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The TLS loader rejects common valid key and store configurations, while the committed certificates expire in 2027.

Review effort: Balanced
Findings: 4 Medium severity · 2 Low severity

Open (6)
What changed in this PR

Adds custom TLS and mutual-TLS configuration for the Java client.

Changes:

  • Adds PEM and PKCS#12 certificate configuration.
  • Builds custom SSL contexts for OkHttp.
  • Adds TLS fixtures and integration tests.
File Description
pom.xml Excludes TLS fixtures from license checks.
CHANGELOG.md Announces TLS/mTLS support.
client-utils/​.../​TlsUtils.java Loads certificates and builds TLS managers.
client/​.../​InfluxDBClientOptions.java Exposes TLS builder options.
client/​.../​InfluxDBClientTest.java Tests TLS and mTLS handshakes.
client/​.../​InfluxDBClientOptionsTest.java Tests TLS option configuration.
client-core/​.../​RestClientTest.java Reorders imports.
client/​.../​tls/​generate-self-signed-cert.sh Generates test credentials.
client/​.../​tls/​influxdb.{crt,key,p12} Provides server fixtures.
client/​.../​tls/​other-server.{crt,key,p12} Provides untrusted-server fixtures.
client/​.../​tls/​client.{crt,key,p12} Provides client fixtures.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread client-utils/src/main/java/com/influxdb/utils/TlsUtils.java Outdated
Comment thread client-utils/src/main/java/com/influxdb/utils/TlsUtils.java Outdated
Comment thread client-utils/src/main/java/com/influxdb/utils/TlsUtils.java Outdated
Comment thread client-utils/src/main/java/com/influxdb/utils/TlsUtils.java Outdated
Comment thread client/src/test/java/com/influxdb/client/tls/generate-self-signed-cert.sh Outdated
Comment thread client/src/test/java/com/influxdb/client/tls/generate-self-signed-cert.sh Outdated

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment thread client-utils/src/main/java/com/influxdb/utils/TlsUtils.java Outdated
Comment thread client-utils/src/main/java/com/influxdb/utils/TlsUtils.java Outdated
Comment thread client/src/main/java/com/influxdb/client/InfluxDBClientOptions.java
Comment thread client/src/main/java/com/influxdb/client/InfluxDBClientOptions.java Outdated
Comment thread CHANGELOG.md Outdated

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Combined PEM configuration is missing and non-RSA private-key fallback is broken.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
Resolved since last review (5)

Comment thread client-utils/src/main/java/com/influxdb/utils/TlsUtils.java Outdated

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The required combined certificate/private-key file configuration is not supported.

Review effort: Balanced
Findings: None

Resolved since last review (1)

@NguyenHoangSon96
NguyenHoangSon96 marked this pull request as ready for review September 30, 2026 07:17

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

mTLS Support (Client Certificates)

3 participants