network: require SSL for HTTPS requests
What changed, and why it matters
This change makes the Monero GUI's built-in web requests actually enforce SSL/TLS encryption when the URL starts with 'https://'. Before, the code picked the port based on the scheme but did not explicitly turn on SSL, which could have allowed an HTTPS request to silently fall back to an unencrypted connection under some conditions. The patch also switches from hardcoded default ports to reading the actual port from the URL.
Treat this as a security hardening fix and include it in the next release. Review other network call sites in the GUI and core wallet to ensure HTTPS requests consistently pass ssl_options_t with SSL enabled. Consider adding runtime tests that verify HTTPS requests fail or warn when SSL cannot be negotiated.
Security signals we found
Explicit SSL/TLS enforcement added for HTTPS scheme
Previous code selected port by scheme but did not pass SSL options
Potential silent downgrade or plaintext transmission risk mitigated
Use of urlParsed.port() instead of hardcoded port improves correctness
Evidence from the diff
In src/qt/network.cpp, the Network::get() helper previously called httpClient->set_server(host, port, {}) with a port string chosen only by scheme and no ssl_options_t argument. The patch introduces an isHttps boolean, maps it to epee::net_utils::ssl_support_t::e_ssl_support_enabled or disabled, uses urlParsed.port() with the appropriate default, and passes an ssl_options_t object forcing SSL on for HTTPS URLs. This closes a potential SSL-stripping/misconfiguration gap where an HTTPS URL might not have been protected by TLS.
Changed components
src/qt/network.cppNetwork::get() HTTP client wrapperMonero GUI wallet network layerInspect captured patch +11 / −1
diff --git a/src/qt/network.cpp b/src/qt/network.cpp
index ba6c94d..574369c 100644
--- a/src/qt/network.cpp
+++ b/src/qt/network.cpp
@@ -144,7 +144,17 @@ QString Network::get(
const QString &contentType /* = {} */) const
{
const QUrl urlParsed(url);
- httpClient->set_server(urlParsed.host().toStdString(), urlParsed.scheme() == "https" ? "443" : "80", {});
+ const bool isHttps = urlParsed.scheme() == "https";
+
+ const auto sslSupport = isHttps
+ ? epee::net_utils::ssl_support_t::e_ssl_support_enabled
+ : epee::net_utils::ssl_support_t::e_ssl_support_disabled;
+
+ httpClient->set_server(
+ urlParsed.host().toStdString(),
+ std::to_string(urlParsed.port(isHttps ? 443 : 80)),
+ {},
+ epee::net_utils::ssl_options_t{sslSupport});
const QString uri = (urlParsed.hasQuery() ? urlParsed.path() + "?" + urlParsed.query() : urlParsed.path());
const http_response_info *pri = NULL;
Why this scored 64/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.