Repository navigation
0.11.0
Breaking change
A Flux speech-to-text or Flux text-to-speech wss:// connection behind a TLS-inspecting proxy or private CA that worked on 0.10.1 only because another crate in your dependency graph enabled tokio-tungstenite/rustls-tls-native-roots or native-tls now fails with UntrustedTlsCertificate until you enable rustls-tls-native-roots on deepgram (or pass Deepgram::tls_config). No public signature changed.
Added
rustls-tls-native-rootscargo feature:wss://WebSocket connections also trust the operating system's certificate store, on top of the bundled webpki roots (never instead of them). For TLS-inspecting proxies (Zscaler, Netskope, …), internal CAs, and self-hosted deployments. Named after thetokio-tungsteniteandreqwestfeatures it mirrors;rustls-native-certshonorsSSL_CERT_FILE/SSL_CERT_DIRin place of the platform store. If the store cannot be loaded (a missing or non-PEMSSL_CERT_FILE, a container with no store), the client continues with the public roots and reports that state explicitly (seeTlsTrustbelow).Deepgram::tls_config(impl Into<Arc<rustls::ClientConfig>>): supply your own rustls configuration once, on the client, and everywss://WebSocket it opens (live transcription, Flux speech-to-text, Flux text-to-speech) uses it verbatim.rustlsis re-exported asdeepgram::rustlsso the versions match.DeepgramError::UntrustedTlsCertificate { host, trust, source }: returned instead of a bareWsErrorwhen the server certificate's issuer is not in the trust roots. The message ends with the remedy that applies to the trust roots actually in effect: enable the feature, install the CA in the OS store, fix anSSL_CERT_FILEwhose roots could not be loaded, or adjust the supplied config. Where a hint mentionsSSL_CERT_FILE, it asks for a PEM bundle holding the CA together with the public roots you rely on, not the CA alone: once set, the variable replaces the OS store for these WebSockets and, on Linux, for the REST client (reqwest's platform verifier reads the same variables), so a file with only the proxy CA would break REST calls to hosts that CA did not sign.deepgram::tlsmodule withTlsTrust(webpki,webpki_and_native,webpki_native_unavailable,custom), the trust roots in effect for a connection.webpki_native_unavailablemeans therustls-tls-native-rootsfeature is on but no native root could be loaded, so only the bundled roots were checked; the load errors are logged attracingWARN level.- Connect-diagnostics records gain
tls_trust(present on everywss://attempt; absent for plaintextws://, where no TLS handshake occurs) andtls_resumed(present once the TLS phase completed). Resumed handshakes are cheaper than full ones, sotls_handshake_msshould be compared within one value oftls_resumed. Additive;schema_versionstays 1.
Changed
- BREAKING: A Flux speech-to-text or Flux text-to-speech
wss://connection behind a TLS-inspecting proxy or private CA that worked on 0.10.1 only because another crate in your dependency graph enabledtokio-tungstenite/rustls-tls-native-rootsornative-tlsnow fails withUntrustedTlsCertificateuntil you enablerustls-tls-native-rootsondeepgram(or passDeepgram::tls_config). No public signature changed. Cause: everywss://WebSocket surface (live transcription, Flux speech-to-text, Flux text-to-speech) now connects through one explicit rustls connector owned by theDeepgramclient, so trust roots and TLS provider are identical across surfaces and no longer depend on which TLS features other crates enable ontokio-tungstenite. Previously only/v1/listenwithconnect-diagnosticsused an explicit connector, and the Flux surfaces took whatever feature unification produced. None of this applies to plaintextws://connections (anhttp://base URL): they perform no TLS handshake and verify no certificate, so neither the feature nortls_configaffects them; keephttp://to local testing and usehttps://whenever credentials or private traffic are involved. - The default TLS configuration is built once per
Deepgramclient (on its first WebSocket connect) and reused, so TLS sessions can be resumed across connections from the same client. Before, a fresh configuration was built per attempt and no session was ever resumed. - The TLS dependencies (
rustls,tokio-rustls,rustls-pki-types,webpki-roots) are now enabled by thelistenandspeakfeatures rather than only byconnect-diagnostics. They were already present in the dependency graph throughtokio-tungstenite; nothing new is downloaded.
Fixed
- With
connect-diagnosticsenabled, connections behind a TLS-inspecting proxy failed even where the same application's 0.10.0 build succeeded: the explicit connector introduced in 0.10.1 bypassed the OS-root merge thattokio-tungstenite/rustls-tls-native-roots(enabled elsewhere in the consumer's dependency graph) had been providing through feature unification. Enablerustls-tls-native-rootsondeepgramto restore that behavior explicitly. - On a client's first connect the OS certificate store (when enabled) is read before any phase timer starts, so it is never charged to
tls_handshake_ms. That first connect'sconnect_duration_mscan therefore exceed the sum of the phase timings by the one-time trust-store load, which is attributed to no phase. A plaintextws://client never resolves TLS at all, so it does not read the store (or log about it). {:?}on aDeepgramclient (or on a sub-client holding one, such asTranscriptionorSpeak) printed the API key or temporary token:reqwest::Client's Debug output includes its default headers, and theAuthorizationheader value was not marked sensitive. It now is, so the header prints asSensitive.
Full changelog: 0.10.1...0.11.0