aboutsummaryrefslogtreecommitdiffstats
path: root/OpenKeychain/src/main/java/org/sufficientlysecure/keychain/util/OkHttpClientFactory.java
diff options
context:
space:
mode:
authorDominik Schürmann <dominik@dominikschuermann.de>2016-04-09 11:53:37 +0200
committerDominik Schürmann <dominik@dominikschuermann.de>2016-04-09 11:53:37 +0200
commit2d762e55da92ef45576967c0d1befef55e7935ea (patch)
treea1a9e991817d8a6379c1146ae6b76b6078dee280 /OpenKeychain/src/main/java/org/sufficientlysecure/keychain/util/OkHttpClientFactory.java
parent4edb805ba1d0e6de966692bbf0ba045fb11211e2 (diff)
downloadopen-keychain-2d762e55da92ef45576967c0d1befef55e7935ea.tar.gz
open-keychain-2d762e55da92ef45576967c0d1befef55e7935ea.tar.bz2
open-keychain-2d762e55da92ef45576967c0d1befef55e7935ea.zip
Okhttp3 cleanups, docs, and fix timeouts for default client
Diffstat (limited to 'OpenKeychain/src/main/java/org/sufficientlysecure/keychain/util/OkHttpClientFactory.java')
-rw-r--r--OpenKeychain/src/main/java/org/sufficientlysecure/keychain/util/OkHttpClientFactory.java51
1 files changed, 34 insertions, 17 deletions
diff --git a/OpenKeychain/src/main/java/org/sufficientlysecure/keychain/util/OkHttpClientFactory.java b/OpenKeychain/src/main/java/org/sufficientlysecure/keychain/util/OkHttpClientFactory.java
index cbbbf6e71..f3606aa2f 100644
--- a/OpenKeychain/src/main/java/org/sufficientlysecure/keychain/util/OkHttpClientFactory.java
+++ b/OpenKeychain/src/main/java/org/sufficientlysecure/keychain/util/OkHttpClientFactory.java
@@ -1,57 +1,74 @@
-package org.sufficientlysecure.keychain.util;
+/*
+ * Copyright (C) 2016 Michał Kępkowski
+ *
+ * This program is free software: you can redistribute it and/or modify
+ * it under the terms of the GNU General Public License as published by
+ * the Free Software Foundation, either version 3 of the License, or
+ * (at your option) any later version.
+ *
+ * This program is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ * GNU General Public License for more details.
+ *
+ * You should have received a copy of the GNU General Public License
+ * along with this program. If not, see <http://www.gnu.org/licenses/>.
+ */
-import okhttp3.CertificatePinner;
-import okhttp3.OkHttpClient;
-import org.sufficientlysecure.keychain.Constants;
+package org.sufficientlysecure.keychain.util;
import java.io.IOException;
import java.net.Proxy;
import java.net.URL;
import java.util.concurrent.TimeUnit;
-/**
- * Created by Michał Kępkowski on 11/03/16.
- */
+import okhttp3.CertificatePinner;
+import okhttp3.OkHttpClient;
+
public class OkHttpClientFactory {
private static OkHttpClient client;
- public static OkHttpClient getSimpleClient(){
- if(client == null){
- client = new OkHttpClient.Builder()
- .connectTimeout(30000, TimeUnit.MILLISECONDS)
- .readTimeout(45000, TimeUnit.MILLISECONDS)
+ public static OkHttpClient getSimpleClient() {
+ if (client == null) {
+ client = new OkHttpClient.Builder()
+ .connectTimeout(5000, TimeUnit.MILLISECONDS)
+ .readTimeout(25000, TimeUnit.MILLISECONDS)
.build();
}
return client;
}
- public static OkHttpClient getPinnedSimpleClient(CertificatePinner pinner){
+ public static OkHttpClient getPinnedSimpleClient(CertificatePinner pinner) {
return new OkHttpClient.Builder()
- .connectTimeout(30000, TimeUnit.MILLISECONDS)
- .readTimeout(45000, TimeUnit.MILLISECONDS)
+ .connectTimeout(5000, TimeUnit.MILLISECONDS)
+ .readTimeout(25000, TimeUnit.MILLISECONDS)
.certificatePinner(pinner)
.build();
}
-
public static OkHttpClient getPinnedClient(URL url, Proxy proxy) throws IOException, TlsHelper.TlsHelperException {
return new OkHttpClient.Builder()
+ // don't follow any redirects for keyservers, as discussed in the security audit
.followRedirects(false)
.followSslRedirects(false)
.proxy(proxy)
+ // higher timeouts for Tor
.connectTimeout(30000, TimeUnit.MILLISECONDS)
.readTimeout(45000, TimeUnit.MILLISECONDS)
+ // use pinned cert with SocketFactory
.sslSocketFactory(TlsHelper.getPinnedSslSocketFactory(url))
.build();
}
- public static OkHttpClient getClient( Proxy proxy) throws IOException, TlsHelper.TlsHelperException {
+ public static OkHttpClient getClient(Proxy proxy) throws IOException, TlsHelper.TlsHelperException {
return new OkHttpClient.Builder()
+ // don't follow any redirects for keyservers, as discussed in the security audit
.followRedirects(false)
.followSslRedirects(false)
.proxy(proxy)
+ // higher timeouts for Tor
.connectTimeout(30000, TimeUnit.MILLISECONDS)
.readTimeout(45000, TimeUnit.MILLISECONDS)
.build();