Skip to content

Conversation

fioan89
Copy link
Collaborator

@fioan89 fioan89 commented Sep 24, 2025

In our codebase we currently have two layers of custom logic:

  • one that alters the SNI in the ClientHello (via a custom SSLSocketFactory)
  • another that compares an alternate hostname against the SAN entries during client-side certificate verification.

This work was done for one of Coder's clients that wants to do auth via certificates instead of API tokens. After recent discussions it turns out the SNI manipulation is not needed, we only need to do custom certificate validation.

In our codebase we currently have two layers of custom logic:
- one that alters the SNI in the ClientHello (via a custom SSLSocketFactory)
- another that compares an alternate hostname against the SAN entries during client-side certificate verification.

This work was done for one of Coder's clients that wants to do auth via certificates instead of API tokens. After recent
discussions it turns out the SNI manipulation is not needed, we only need to do custom certificate validation.
Copy link
Contributor

Qodana Community for JVM

33 new problems were found

Inspection name Severity Problems
Usage of API marked for removal 🔴 Failure 13
Local 'var' is never modified and can be declared as 'val' 🔶 Warning 1
Incorrect string capitalization 🔶 Warning 1
Constant conditions 🔶 Warning 1
Usage of redundant or deprecated syntax or deprecated symbols 🔶 Warning 1
Throwable not thrown 🔶 Warning 1
Redundant nullable return type 🔶 Warning 1
Unused symbol 🔶 Warning 1
Convert 'object' to 'data object' ◽️ Notice 5
Class member can have 'private' visibility ◽️ Notice 3
String concatenation that can be converted to string template ◽️ Notice 2
Argument could be converted to 'Set' to improve performance ◽️ Notice 1
Return or assignment can be lifted out ◽️ Notice 1
Redundant lambda arrow ◽️ Notice 1

💡 Qodana analysis was run in the pull request mode: only the changed files were checked

View the detailed Qodana report

To be able to view the detailed Qodana report, you can either:

  1. Register at Qodana Cloud and configure the action
  2. Use GitHub Code Scanning with Qodana
  3. Host Qodana report at GitHub Pages
  4. Inspect and use qodana.sarif.json (see the Qodana SARIF format for details)

To get *.log files or any other Qodana artifacts, run the action with upload-result option set to true,
so that the action will upload the files as the job artifacts:

      - name: 'Qodana Scan'
        uses: JetBrains/qodana-action@v2023.3.2
        with:
          upload-result: true
Contact Qodana team

Contact us at qodana-support@jetbrains.com

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant