Shopify / Shopify/shopify_python_api
`Certificate verify failed` on `request_token`
未关闭
还没有人认领这个 Issue。
feature request
- 主要语言
- Python
- 星标
- 1.4k
- 派生
- 388
- 平均合并
- 5 小时 39 分钟
- 30 天内合并 PR
- 1
描述
Looks like Shopify's servers don't handle well TLS v1.2; TLS v1.1 must be used in order to retrieve the access_token correctly without bypassing certificate validation.
We should update the library so that TLS v1.1 is used everywhere, and people don't have to figure it out by themselves.
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
调研方向
从库的 request_token 路径开始,跟踪 TLS 设置是如何应用到 Shopify 请求的。在确定受影响的调用点之前,先重现证书验证失败;完成的标准是 access_token 获取使用 TLS v1.1,且不绕过证书验证。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- python
- 领域
- api, security
- Issue 类型
- 缺陷
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 活跃度
- 停滞
- 描述清晰度
- 基本清楚
- 新手友好度
- 35/100