refactor(client): owned RetryConfig + TLS/mTLS test coverage (HY-06, COV-02)

- HttpClientConfig.retry_policy: ExponentialBackoff (semver anchor to a
  reqwest-retry concrete type) replaced by retry: RetryConfig — an
  owned struct of plain scalars (max_retries, initial_backoff,
  max_retry_interval, defaults matching the previous backoff exactly);
  the ExponentialBackoff policy is built internally by the middleware
  stack; no reqwest_retry type is public anymore
- ClientCertConfig fields documented (none had docs)
- new tests/client_tls.rs: per-test rcgen private PKI + tokio-rustls
  HTTPS server; drives the real SharedHttpClient through
  HttpClientConfig file paths — CA-bundle success path, private-roots
  rejection (source-chain assertion: invalid peer certificate),
  mTLS end-to-end with client identity, mTLS rejection without
  identity, and reload-to-CA-bundle interplay
- dev-deps: rcgen 0.14, tokio-rustls 0.26, rustls 0.23 (aws_lc_rs),
  rustls-pki-types 1, uuid

Verified: cargo test (288 + 5 TLS), --all-features (359 + suites),
--no-default-features (288; pre-existing warnings only), clippy
--all-targets -D warnings (default + all-features), fmt --check,
cargo doc --no-deps.

Tasks: review-001-client-config-and-cert-coverage
This commit is contained in:
2026-08-30 07:24:34 +00:00
parent 1572a9d2d0
commit edbda6605b
5 changed files with 711 additions and 495 deletions
+5
View File
@@ -59,6 +59,11 @@ http-body-util = "0.1"
tower = { version = "0.5", features = ["util"] }
tokio-tungstenite = { version = "0.29", default-features = false, features = ["connect"] }
openapiv3 = "2"
rcgen = "0.14"
tokio-rustls = "0.26"
rustls = { version = "0.23", default-features = false, features = ["aws_lc_rs", "std", "tls12"] }
rustls-pki-types = "1"
uuid = { version = "1", features = ["v4"] }
[[test]]
name = "ws_upgrade_session"