You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
documentation for requests.session.request(verify=...) duplicates requests.request() even where it is different #7399
Either a boolean, in which case it controls whether we verify the server’s TLS certificate, or a string, in which case it must be a path to a CA bundle to use. Defaults to True.
I suggest rewording both statements, because as they stand they make figuring what went wrong with setting the correct CA bundle way harder than it should be:
Passing bool not only controls whether the certificate is verified, it also resets the root store to be verified against.
The default for the method does not behave like True - leaving it unspecified simply defers to the session, as it should.. session in turn may very well have verify=False.
This result means that libraries that opt to use the supposedly-default parameter value of True are doing something meaningfully different from those that use the actual-default parameter of None (typically: by not mentioning the parameter).
Thanks for opening this issue, @biredel. None is not an intended value users should be passing for verify. I agree we could potentially reword the docstring though.
The current wording is intended to convey you do not need to pass a default, Requests will handle everything (which is what happens). If you choose to hardcode the documented default per request, you're encountering precedence decisions (explicit request() input will supercede Session settings).
If we changed it, it would probably be to convey it "defaults to the Session value, True by default".
Docs currently state:
I suggest rewording both statements, because as they stand they make figuring what went wrong with setting the correct CA bundle way harder than it should be:
os.environprecedence, but I understand that one is currently #WONTFIX as per Session.verify=False ignored when REQUESTS_CA_BUNDLE environment variable is set #3829)Documentation appears to state
Actual Result
Reproduction Steps
This result means that libraries that opt to use the supposedly-default parameter value of True are doing something meaningfully different from those that use the actual-default parameter of None (typically: by not mentioning the parameter).
System Information
{ "chardet": { "version": "4.0.0" }, "charset_normalizer": { "version": "3.4.4" }, "cryptography": { "version": "" }, "idna": { "version": "3.3" }, "implementation": { "name": "CPython", "version": "3.10.12" }, "platform": { "release": "6.8.0-110-generic", "system": "Linux" }, "pyOpenSSL": { "openssl_version": "", "version": null }, "requests": { "version": "2.33.1" }, "system_ssl": { "version": "30000020" }, "urllib3": { "version": "2.6.3" }, "using_charset_normalizer": false, "using_pyopenssl": false }