When using this module with a Sentry server that has a self-signed certificate, there isn't a way to tell the Raven PHP library not to verify the SSL certificate of the server. This means that messages don't get submitted to Sentry, and fail silently (no SSL error is logged in PHP or Drupal watchdog).
I've created a patch which adds a checkbox option to the Sentry admin form allowing the verify_ssl option to be set. It defaults to "True" (SSL certificates must be verified).
Another avenue for exploration is to perform a test message when a Drupal status report is generated, which would provide a way of verifying that this module can successfully contact Sentry (rather than just indicating whether or not it's enabled/configured).
| Comment | File | Size | Author |
|---|---|---|---|
| #27 | 2653134-d8-27.patch | 3.59 KB | mfb |
Comments
Comment #3
justinstandring commentedUpdating this to 'Needs Review' - the test-bot is currently throwing false results: https://www.drupal.org/node/2645590
Comment #4
mfbFrom a security/authenticity perspective it would actually be better to allow the site admin to provide a CA cert via the ca_cert option rather than disabling SSL verification.
Comment #5
justinstandring commentedGood point. I've made a new patch that provides three options for SSL verification:
When 'Verify against a CA certificate' is selected, a textfield is shown to enter the path to the certificate file. I've grouped these options with 'Timeout' under a fieldset called 'Connection Settings'. I've attached a screenshot of this.
Again, the module defaults to verifying SSL by default (and if the certificate file is non-existent).
Comment #7
mfbok I added some minimal tests so patches will be green now.
Comment #8
mfba bit of refactoring, and make the connection settings collapsed by default.
Comment #9
mfb@justinstandring have you verified that the CA cert setting is working?
Comment #10
justinstandring commentedYes - I've tested all three options
Comment #12
mfbComment #14
mfbComment #15
dakku commentedPlease see quick port to D8 branch.
Comment #16
dakku commentedComment #17
mfbWe don't need
raven_- it's redundant as we're already in raven.settingsComment #18
dakku commented@mfb here is a re-rolled one..
Comment #19
dakku commentedComment #21
dakku commentedre-rolled against latest dev..
Comment #22
mfbLGTM. have you tested all the options?
Comment #23
dakku commented@mgf seemed good one my side :)
Do let me know if you come across something!
Comment #24
mfbCan you use dependency injection for \Drupal::service('file_system')?
FYI to catch this you can run phpcs --standard=DrupalPractice .
(yes there is actually one other place in RavenConfigForm.php where \Drupal slipped in..)
Comment #25
mfbComment #27
mfbTurns out we cannot use the file_system service when initializing a logger, because file_system depends on logger.
So, as a work-around for now I am simply calling realpath() function rather than the realpath() method.
Comment #29
mfbCommitted! Please update this issue if you find any trouble w/ the new feature.