Skip to content

Commit 61270bf

Browse files
Merge pull request #21 from niteeshkanna-sh/claude/stoic-rubin-fnglq7
Let the panel check accept the same certificate the deploy already does
2 parents cc83613 + debe0bd commit 61270bf

1 file changed

Lines changed: 14 additions & 1 deletion

File tree

‎.github/workflows/deploy-admin.yml‎

Lines changed: 14 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -161,8 +161,21 @@ jobs:
161161
# handshake and a blocked data connection all look exactly like an
162162
# empty directory -- and the check then reports the folder is wrong
163163
# when the truth is that it never got to look.
164+
# --insecure encrypts the connection but does not verify the
165+
# server's certificate. That is a real weakening and it is worth
166+
# being explicit about why it is here: this host presents a
167+
# certificate curl will not validate, and the deploy step below
168+
# completes FTPS against it regardless -- so the upload, carrying
169+
# the same credentials, already crosses an unverified channel.
170+
# A check that is stricter than the deploy it guards blocks work
171+
# without protecting anything; it did exactly that on its first
172+
# run, reporting a folder as missing when it had simply been
173+
# refused the handshake.
174+
#
175+
# The fix that would let this be strict is a valid certificate on
176+
# the FTP host, which is Hostinger's to provide.
164177
set +e
165-
listing="$(curl --silent --show-error --ssl-reqd --list-only \
178+
listing="$(curl --silent --show-error --ssl-reqd --insecure --list-only \
166179
--connect-timeout 20 --max-time 60 \
167180
--config "$cfg" 2>"$cfg.err")"
168181
rc=$?

0 commit comments

Comments
 (0)