Skip to content

fix: enable HTTP/2 for CLI RDAP requests - #57

Merged
robtme merged 3 commits into
openrdap:mainfrom
RyougikiMikiya:fix-twnic-http2
Sep 23, 2026
Merged

robtme merged 3 commits into
openrdap:mainfrom
RyougikiMikiya:fix-twnic-http2

Conversation

@RyougikiMikiya

@RyougikiMikiya RyougikiMikiya commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Fix RDAP CLI queries against servers that require HTTP/2, such as TWNIC.

Problem

The CLI creates a custom http.Transport with a custom TLS configuration. In this case, Go does not automatically attempt HTTP/2.

TWNIC rejects HTTP/1.1 requests with 426 Upgrade Required, causing queries such as:

rdap cheers.com.tw -v
# OpenRDAP v0.10.2
#
# rdap: Configuring query...
# rdap: Using disk cache (/root/.cache/openrdap)
# rdap: Bootstrap URL is default 'https://data.iana.org/rdap/'
# rdap: Bootstrap cache TTL set to 3600 seconds
# rdap: Timeout is 30 seconds
#
# client: Running...
# client: Request type  : domain
# client: Request query : cheers.com.tw
# client: Request URL   : TBD, bootstrap required
#   bootstrap: Looking up...
#   bootstrap: Question type : dns
#   bootstrap: Question query: cheers.com.tw
#   bootstrap: Cache state: dns.json: good
#   bootstrap: Using cached Service Registry file
#   bootstrap: Looked up 'cheers.com.tw'
#   bootstrap: Matching entry 'tw'
#   bootstrap: Service URL #1: 'https://ccrdap.twnic.tw/tw/'
# client: RDAP URL #0 is https://ccrdap.twnic.tw/tw/domain/cheers.com.tw
# client: GET https://ccrdap.twnic.tw/tw/domain/cheers.com.tw
# client: status-code=426, content-type=, length=0 bytes, duration=1.051906443s
#
# rdap: Finished in 1.053641356s
# Error: No RDAP servers responded successfully (tried 1 server(s))

to fail with:

Error: No RDAP servers responded successfully

Changes

  • Enable HTTP/2 explicitly with ForceAttemptHTTP2: true.
  • Add a regression test using an HTTP/2-only test server.

Verification

  • go test -race ./...
  • go vet ./...
  • Verified successfully against the live TWNIC RDAP endpoint:

https://ccrdap.twnic.tw/tw/domain/cheers.com.tw

The query now returns HTTP 200 and is decoded successfully.

Summary by CodeRabbit

  • Bug Fixes
    • Improved CLI connectivity with HTTP/2 when custom TLS settings are configured.
    • Enables successful communication with HTTP/2-only servers when using insecure connections.
    • Preserves standard proxy and connection behavior while applying custom TLS settings, helping requests work consistently across different network environments.

@coderabbitai

coderabbitai Bot commented Sep 17, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

Next included review available in 37 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used all 2 included reviews currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 9208bad5-95f8-4579-af90-d172c93dadd3

📥 Commits

Reviewing files that changed from the base of the PR and between 673c55f and c18b157.

📒 Files selected for processing (2)
  • cli.go
  • cli_test.go

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 52d61042-7b92-4a86-889b-c3d73ba72ce2

📥 Commits

Reviewing files that changed from the base of the PR and between dbb8035 and 673c55f.

📒 Files selected for processing (1)
  • cli.go

Included review availability: Your plan provides up to 2 included reviews per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

RunCLI clones http.DefaultTransport when it is an *http.Transport and applies tlsConfig to the clone. Otherwise, it creates a transport with ProxyFromEnvironment and ForceAttemptHTTP2 enabled. A new test uses a TLS HTTP/2 fixture that returns HTTP 426 for non-HTTP/2 requests and checks successful output for example.cz.

Merge Risk: ⚪ Minimal · up to 673c5

The HTTP/2 change has no identified issue that needs resolution before merge.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 50.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 4 functions across 2 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed Title matches main change: enable HTTP/2 for CLI RDAP requests.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Inherits HTTP/2, proxy, and timeout defaults instead of rebuilding
them by hand.
@robtme
robtme merged commit 64c8c7d into openrdap:main Sep 23, 2026
@robtme

robtme commented Sep 23, 2026

Copy link
Copy Markdown
Member

Great stuff, thanks @RyougikiMikiya! I slightly refactored the transport to instead clone the default Go transport, as this also bakes in default timeouts and such which we should also be using.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants