{ "id": "120699", "key": "TIMOB-15385", "fields": { "issuetype": { "id": "1", "description": "A problem which impairs or prevents the functions of the product.", "name": "Bug", "subtask": false }, "project": { "id": "10153", "key": "TIMOB", "name": "Titanium SDK/CLI", "projectCategory": { "id": "10100", "description": "Titanium and related SDKs used in application development", "name": "Client" } }, "fixVersions": [], "resolution": { "id": "5", "description": "All attempts at reproducing this issue failed, or not enough information was available to reproduce the issue. Reading the code produces no clues as to why this behavior would occur. If more information appears later, please reopen the issue.", "name": "Cannot Reproduce" }, "resolutiondate": "2014-03-26T20:24:20.000+0000", "created": "2013-10-01T21:17:08.000+0000", "priority": { "name": "Low", "id": "4" }, "labels": [ "supportTeam" ], "versions": [], "issuelinks": [], "assignee": { "name": "ingo", "key": "ingo", "displayName": "Ingo Muschenetz", "active": true, "timeZone": "America/Los_Angeles" }, "updated": "2017-03-27T22:16:28.000+0000", "status": { "description": "The issue is considered finished, the resolution is correct. Issues which are closed can be reopened.", "name": "Closed", "id": "6", "statusCategory": { "id": 3, "key": "done", "colorName": "green", "name": "Done" } }, "components": [ { "id": "10202", "name": "Android", "description": "Android Platform" } ], "description": "Setting the validatesSecureCertificate property to true in the HTTPClient module does not work on the Android platform. Requests to invalid SSL sites are allowed to go through without exception. This feature does work as designed for iOS.\r\n\r\nExample:\r\n{code}\r\nvar xhr = Ti.Network.createHTTPClient();\r\nxhr.validatesSecureCertificate = true;\r\n{code}\r\n", "attachment": [], "flagged": false, "summary": "HTTPClient Not Validating SSL Certificate on Android", "creator": { "name": "bwakeman", "key": "bwakeman", "displayName": "Ben Wakeman", "active": true, "timeZone": "America/New_York" }, "subtasks": [], "reporter": { "name": "bwakeman", "key": "bwakeman", "displayName": "Ben Wakeman", "active": true, "timeZone": "America/New_York" }, "environment": "Android platform", "comment": { "comments": [ { "id": "273540", "author": { "name": "bwakeman", "key": "bwakeman", "displayName": "Ben Wakeman", "active": true, "timeZone": "America/New_York" }, "body": "This issue was discovered by the Bed Bath & Beyond security team with build of the mobile app on the Titanium 3.1.1 SDK using and Android 4.2 phone.", "updateAuthor": { "name": "bwakeman", "key": "bwakeman", "displayName": "Ben Wakeman", "active": true, "timeZone": "America/New_York" }, "created": "2013-10-01T21:47:41.000+0000", "updated": "2013-10-01T21:47:41.000+0000" }, { "id": "273920", "author": { "name": "mgoff", "key": "mgoff", "displayName": "Michael Goff", "active": true, "timeZone": "America/Los_Angeles" }, "body": "Does this mean the value is not true by default?", "updateAuthor": { "name": "mgoff", "key": "mgoff", "displayName": "Michael Goff", "active": true, "timeZone": "America/Los_Angeles" }, "created": "2013-10-05T00:35:25.000+0000", "updated": "2013-10-05T00:35:25.000+0000" }, { "id": "274014", "author": { "name": "rtlechuga", "key": "rtlechuga", "displayName": "Radamantis Torres-Lechuga", "active": false, "timeZone": "Asia/Dubai" }, "body": "[~bwakeman] . Can you provide a reproducible test case? We need more information and steps to reproduce the issue. \nAlso, please add Android OS version, Android phone model, Titanium SDK , Studio version and the operating system version.\nThanks", "updateAuthor": { "name": "rtlechuga", "key": "rtlechuga", "displayName": "Radamantis Torres-Lechuga", "active": false, "timeZone": "Asia/Dubai" }, "created": "2013-10-07T16:28:29.000+0000", "updated": "2013-10-07T16:28:29.000+0000" }, { "id": "274027", "author": { "name": "bwakeman", "key": "bwakeman", "displayName": "Ben Wakeman", "active": true, "timeZone": "America/New_York" }, "body": "@Michael - no it has nothing to do with the default value of the property, it has to do with the fact that even when the value is set to true, it is not validating SSL requests on android.\r\n\r\n@Radamantis - I've again forwarded a request to the Bed Bath and Beyond security team who raised the issue so they can provide us with the means to validate the issue.", "updateAuthor": { "name": "bwakeman", "key": "bwakeman", "displayName": "Ben Wakeman", "active": true, "timeZone": "America/New_York" }, "created": "2013-10-07T16:46:29.000+0000", "updated": "2013-10-07T16:46:29.000+0000" }, { "id": "298856", "author": { "name": "ingo", "key": "ingo", "displayName": "Ingo Muschenetz", "active": true, "timeZone": "America/Los_Angeles" }, "body": "Resolving as cannot reproduce. Needs confirmation by QE before closing.", "updateAuthor": { "name": "ingo", "key": "ingo", "displayName": "Ingo Muschenetz", "active": true, "timeZone": "America/Los_Angeles" }, "created": "2014-03-26T20:24:20.000+0000", "updated": "2014-03-26T20:24:20.000+0000" } ], "maxResults": 8, "total": 8, "startAt": 0 } } }