Uh oh!
There was an error while loading. Please reload this page.
Do not fail on partial trust warning. - #9384
Conversation
There was a problem hiding this comment.
Pull Request Overview
This PR addresses an issue where the HTTPS developer certificate might be partially trusted, preventing a hard failure on a non-zero exit code from the dotnet dev-certs command. The changes include new tests to verify both the success and failure paths and an update to CertificateService to detect and warn when a partial trust condition is encountered.
Reviewed Changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
| tests/Aspire.Cli.Tests/Certificates/CertificateServiceTests.cs | Added tests to cover the partial trust scenario |
| src/Aspire.Cli/Certificates/CertificateService.cs | Modified the certificate service to detect a partial trust message and continue startup with a warning |
Comments suppressed due to low confidence (1)
src/Aspire.Cli/Certificates/CertificateService.cs:67
- Consider reusing the outputLines variable instead of calling ensureCertificateCollector.GetLines() again to avoid potential discrepancies if the collector's state changes.
interactionService.DisplayLines(ensureCertificateCollector.GetLines());
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
This PR fixes an issue that was reported where the underlying shell out to
dotnet dev-certsto trust a certificate might result in a non-zero exit code where the cert is partially trusted.In these circumstances we probably want to "let it slide" and continue starting up the apphost because there are lots of corner cases around certificate trust particularly on Linux distros which might result in this issue.
Rather than hard blocking we detect we are in this partial trust situation and just display a warning (mostly to help our own diagnostics if it later doesn't actually work).
We should consider modifying dev-certs to return a different exit code for this partial trust situation.