Lighthouse has a new layout. Prefer the old one? Return to the old layout, and switch back any time from the link at the top of each page.

This project is archived and is in readonly mode.

ActiveResource should allow SSL verification

#781

As shipped right now, all ARes clients are subject to man-in-the-middle attacks by any server claiming to be a trusted API provider. We're using ActiveResource in some security-sensitive internal applications, and the lack of SSL certificate verification is worrisome.

I understand that configuring OpenSSL to properly verify all certificates in an application may be too high a barrier for some applications, but it would be preferable to at least have the option to override the default 'trust anyone' setting made in active_resource/connection.rb.

I've attached a simple patch against the current edge tree as an example; the particular configuration variable name is less important to me than the ability to turn on certificate verification in cases where the certificate infrastructure allows it.

Reported by rcoder · August 8th, 2008 @ 12:33 AM

State: duplicate
Milestone: 2.x
Assigned to: nobody
Importance: none

Activity

  1. DHH
    DHH
    • State changed from new to incomplete

    I think this is reasonable, but we need tests and documentation.

    September 10th, 2008 @ 06:09 AM

  2. CancelProfileIsBroken
    CancelProfileIsBroken
    • Tag changed from activeresource, patch, security, ssl to activeresource, bugmash, patch, security, ssl

    August 3rd, 2009 @ 03:13 PM

  3. Jeremy Kemper
    Jeremy Kemper
    • State changed from incomplete to duplicate
    • Tag changed from activeresource, bugmash, patch, security, ssl to activeresource, patch, security, ssl

    August 9th, 2009 @ 09:24 PM