Remove OkHttp <v3 and TrustKit hostname verification patches

Looks like they're actually the same implementation, it's just that
TrustKit inlined OkHttp's version.

These aren't required, as they doesn't implement certificate pinning,
and it's trivial to work around with any functional MitM setup: you
just have to return valid certs with the right hostnames. No need to
mess with that, best to check it properly, so dropped.
This commit is contained in:
Tim Perry
2023-10-19 21:51:51 +02:00
parent 6f6d8cce6f
commit 2860d14600
-26
View File
@@ -162,34 +162,8 @@ const PINNING_FIXES = {
}
],
'com.squareup.okhttp.internal.tls.OkHostnameVerifier': [
{
methodName: 'verify',
overload: ['java.lang.String', 'java.security.cert.X509Certificate'],
replacement: () => RETURN_TRUE
},
{
methodName: 'verify',
overload: ['java.lang.String', 'javax.net.ssl.SSLSession'],
replacement: () => RETURN_TRUE
}
],
// --- Trustkit (https://github.com/datatheorem/TrustKit-Android/)
'com.datatheorem.android.trustkit.pinning.OkHostnameVerifier': [
{
methodName: 'verify',
overload: ['java.lang.String', 'javax.net.ssl.SSLSession'],
replacement: () => RETURN_TRUE
},
{
methodName: 'verify',
overload: ['java.lang.String', 'java.security.cert.X509Certificate'],
replacement: () => RETURN_TRUE
}
],
'com.datatheorem.android.trustkit.pinning.PinningTrustManager': [
{
methodName: 'checkServerTrusted',