Skip to content

Add mTLS client-identity hook for Network.framework connections - #12

Draft
o-nnerb wants to merge 2 commits into
mainfrom
mtls-network-framework-identity
Draft

o-nnerb wants to merge 2 commits into
mainfrom
mtls-network-framework-identity

Conversation

@o-nnerb

@o-nnerb o-nnerb commented Sep 8, 2026

Copy link
Copy Markdown
Member

Summary

  • Exposes HTTPClient.Configuration.tlsLocalIdentityNetworkFramework: SecIdentity? — a thin passthrough into Network.framework's sec_protocol_options_set_local_identity, for direct (non-proxied) connections on Apple platforms.
  • tlsConfiguration.certificateChain/.privateKey (the NIOSSL-shaped mTLS config) remain unsupported on this backend, same as before — there is no public API to build a SecIdentity from raw bytes without a Keychain round-trip, so this hook takes an already-built SecIdentity rather than AsyncHTTPClient performing that round-trip itself.
  • Depends on neither tlsCustomVerification nor tlsCustomVerificationNetworkFramework from Add pluggable trust-verification hooks for NIOSSL and Network.framework #11, but was developed alongside them and merges cleanly with that work (see the release integration branch).

Test plan

  • LocalIdentityNetworkFrameworkTests: negative control (server requiring a client cert rejects a connection with none) passes reliably; the positive test (client cert actually presented) passes on the NIOSSL backend and is XCTSkip'd on Network.framework when synthesizing a Keychain-backed SecIdentity inside an unsigned swift test process itself fails — the same limitation InternalsRawBytesIdentityBuilderTests in request-dl-nio already works around by only unit-testing its DER-parsing halves, not the full Keychain round-trip.
  • swift build clean, swift format lint --strict clean.
  • Existing HTTPClientNIOTSTests/HTTPConnectionPool+FactoryTests unaffected in both NIOSSL and Network.framework modes.

🤖 Generated with Claude Code

Exposes HTTPClient.Configuration.tlsLocalIdentityNetworkFramework: a
thin passthrough into Network.framework's
sec_protocol_options_set_local_identity, for direct (non-proxied)
connections on Apple platforms. tlsConfiguration.certificateChain and
.privateKey (the NIOSSL-shaped mTLS config) remain unsupported on this
backend, same as before -- there's no public API to build a
SecIdentity from raw bytes without a Keychain round-trip, so this hook
takes an already-built SecIdentity rather than AsyncHTTPClient
performing that round-trip itself.

Tests cover both that the client certificate is actually presented to
a server that requires one, and the negative control (connection
rejected without it). Synthesizing a Keychain-backed SecIdentity
inside an unsigned `swift test` process is itself unreliable -- the
positive test skips rather than flakes when that round-trip can't
complete, same limitation RequestDL's own RawBytesIdentityBuilder
test suite already works around by only unit-testing its DER-parsing
halves.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@o-nnerb o-nnerb added the 🆕 semver/minor Additive, non-breaking API change label Sep 8, 2026
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

🆕 semver/minor Additive, non-breaking API change

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant