mirror of
https://github.com/XRPLF/rippled.git
synced 2026-09-27 23:38:08 +00:00
The scheme guard only ran when tls_client_cert was set, so use_tls=1 against an http endpoint booted: the CA file was checked for readability, then the exporter read TLS off the URL scheme alone and sent spans in the clear. An operator who asks for TLS should get TLS or a startup error. Widen the guard to every use_tls=1 node. tls_client_cert already requires use_tls=1, so this strictly widens the old condition. The error message and the function's description now name use_tls rather than the certificate key. one_way_tls_on_a_plain_http_endpoint_is_accepted pinned the old behaviour and is flipped to _throws, asserting the scheme message, the endpoint key and the URL. Three cases that sent use_tls=1 at an http endpoint while asserting a file error now set an https endpoint, so the scheme guard cannot be what throws.