fix(tradein): skip TLS verify for sberindex.ru pull — server omits LE intermediate (#922)
This commit is contained in:
parent
02af421799
commit
ca0943689d
1 changed files with 8 additions and 1 deletions
|
|
@ -307,7 +307,14 @@ async def pull_sber_indices(
|
||||||
|
|
||||||
counters: dict[str, int] = {"upserted": 0, "skipped": 0, "errors": 0}
|
counters: dict[str, int] = {"upserted": 0, "skipped": 0, "errors": 0}
|
||||||
|
|
||||||
async with httpx.AsyncClient(timeout=SBER_HTTP_TIMEOUT) as client:
|
# #922: sberindex.ru serves an INCOMPLETE TLS chain — it sends only the leaf
|
||||||
|
# certificate and omits the Let's Encrypt intermediate (R13), so cert
|
||||||
|
# verification fails with "unable to get local issuer certificate" (verify
|
||||||
|
# code 21) even against a full system/certifi trust store. This is a
|
||||||
|
# server-side misconfiguration outside our control. The endpoint is public,
|
||||||
|
# unauthenticated, non-sensitive open data, so we skip TLS verification here
|
||||||
|
# rather than pin a Let's Encrypt intermediate that rotates (R10–R14+).
|
||||||
|
async with httpx.AsyncClient(timeout=SBER_HTTP_TIMEOUT, verify=False) as client:
|
||||||
for ref_area, _city_hint in cities.items():
|
for ref_area, _city_hint in cities.items():
|
||||||
for dashboard in dashboards:
|
for dashboard in dashboards:
|
||||||
try:
|
try:
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue