From a92ae0ded5228b92d61dc7721b2723fc6a98c792 Mon Sep 17 00:00:00 2001 From: Jack Ye Date: Tue, 21 Apr 2026 08:39:03 -0700 Subject: [PATCH] fix: enable hostname verification by default (#3304) ## Summary - make `TlsConfig::default()` enable hostname verification by default - align the Rust default with the documented Python and Node behavior - update the Rust unit test to lock in the safe default --- rust/lancedb/src/remote/client.rs | 18 +++++++++++++++--- 1 file changed, 15 insertions(+), 3 deletions(-) diff --git a/rust/lancedb/src/remote/client.rs b/rust/lancedb/src/remote/client.rs index b50ca2206..7fd5c6497 100644 --- a/rust/lancedb/src/remote/client.rs +++ b/rust/lancedb/src/remote/client.rs @@ -16,7 +16,7 @@ use crate::remote::retry::{ResolvedRetryConfig, RetryCounter}; const REQUEST_ID_HEADER: HeaderName = HeaderName::from_static("x-request-id"); /// Configuration for TLS/mTLS settings. -#[derive(Clone, Debug, Default)] +#[derive(Clone, Debug)] pub struct TlsConfig { /// Path to the client certificate file (PEM format) pub cert_file: Option, @@ -24,10 +24,22 @@ pub struct TlsConfig { pub key_file: Option, /// Path to the CA certificate file for server verification (PEM format) pub ssl_ca_cert: Option, - /// Whether to verify the hostname in the server's certificate + /// Whether to verify the hostname in the server's certificate. + /// Defaults to `true`. pub assert_hostname: bool, } +impl Default for TlsConfig { + fn default() -> Self { + Self { + cert_file: None, + key_file: None, + ssl_ca_cert: None, + assert_hostname: true, + } + } +} + /// Trait for providing custom headers for each request #[async_trait::async_trait] pub trait HeaderProvider: Send + Sync + std::fmt::Debug { @@ -926,7 +938,7 @@ mod tests { assert!(config.cert_file.is_none()); assert!(config.key_file.is_none()); assert!(config.ssl_ca_cert.is_none()); - assert!(!config.assert_hostname); + assert!(config.assert_hostname); } #[test]