{"record":{"id":"d718623b638aac29","repo":"aio-libs/aiohttp","slug":"ssl-should-be-sslcontext-fingerprint-or-bool-go-d71862","errorCode":null,"errorMessage":"ssl should be SSLContext, Fingerprint, or bool, got {ssl!r} instead.","messagePattern":"ssl should be SSLContext, Fingerprint, or bool, got (.+?) instead\\.","errorType":"exception","errorClass":"TypeError","httpStatus":null,"severity":"error","filePath":"aiohttp/connector.py","lineNumber":1025,"sourceCode":"        limit_per_host: int = 0,\n        enable_cleanup_closed: bool = False,\n        timeout_ceil_threshold: float = 5,\n        happy_eyeballs_delay: float | None = 0.25,\n        interleave: int | None = None,\n        socket_factory: SocketFactoryType | None = None,\n        ssl_shutdown_timeout: _SENTINEL | None | float = sentinel,\n    ):\n        super().__init__(\n            keepalive_timeout=keepalive_timeout,\n            force_close=force_close,\n            limit=limit,\n            limit_per_host=limit_per_host,\n            enable_cleanup_closed=enable_cleanup_closed,\n            timeout_ceil_threshold=timeout_ceil_threshold,\n        )\n\n        if not isinstance(ssl, SSL_ALLOWED_TYPES):\n            raise TypeError(\n                \"ssl should be SSLContext, Fingerprint, or bool, \"\n                f\"got {ssl!r} instead.\"\n            )\n        self._ssl = ssl\n\n        self._resolver: AbstractResolver\n        if resolver is None:\n            self._resolver = DefaultResolver()\n            self._resolver_owner = True\n        else:\n            self._resolver = resolver\n            self._resolver_owner = False\n\n        self._use_dns_cache = use_dns_cache\n        self._cached_hosts = _DNSCacheTable(\n            ttl=ttl_dns_cache, max_size=dns_cache_max_size\n        )\n        self._throttle_dns_futures: dict[tuple[str, int], set[asyncio.Future[None]]] = (","sourceCodeStart":1007,"sourceCodeEnd":1043,"githubUrl":"https://github.com/aio-libs/aiohttp/blob/d041d4d0fd48c3f0832084d33be16cf1c4835f85/aiohttp/connector.py#L1007-L1043","documentation":"Raised by TCPConnector.__init__ when the ssl argument is not in SSL_ALLOWED_TYPES (SSLContext, Fingerprint, or bool). The ssl parameter controls TLS behavior for every connection the connector makes, so an unexpected type would propagate ambiguously; aiohttp rejects it immediately with the offending value echoed via %r.","triggerScenarios":"Passing ssl='True' (string), ssl=None (NoneType is not allowed - use the sentinel or False), ssl=an SSL enum, ssl=a pathlib path to a cert, or ssl=some_object from a misread tutorial.","commonSituations":"Confusing ssl with verify_ssl/cert loading helpers; passing an ssl enum from another library; copy-pasting code that targeted a different HTTP client; deserializing config from JSON where True became 'True'.","solutions":["Pass True (verify, use default context), False (disable verification - not recommended), an ssl.SSLContext, or a Fingerprint.","To load a custom CA bundle, build an SSLContext and pass that, not a file path.","If you need 'no ssl', omit the argument or pass the sentinel rather than None.","Type-check config-derived ssl values before constructing the connector."],"exampleFix":"# before\nconnector = aiohttp.TCPConnector(ssl='/etc/ssl/certs/ca.pem')\n# after\nimport ssl\nctx = ssl.create_default_context(cafile='/etc/ssl/certs/ca.pem')\nconnector = aiohttp.TCPConnector(ssl=ctx)","handlingStrategy":"type-guard","validationCode":"import ssl\nfrom aiohttp import Fingerprint\n\ndef valid_ssl(value) -> bool:\n    return isinstance(value, (ssl.SSLContext, Fingerprint, bool))\n\nassert valid_ssl(configured_ssl), 'ssl must be SSLContext, Fingerprint, or bool'","typeGuard":"import ssl\nfrom aiohttp import Fingerprint\nfrom typing import Union\n\ndef is_ssl_allowed(value) -> bool:\n    return isinstance(value, (ssl.SSLContext, Fingerprint, bool))","tryCatchPattern":"try:\n    connector = aiohttp.TCPConnector(ssl=configured_ssl)\nexcept TypeError as exc:\n    if 'ssl should be' in str(exc):\n        connector = aiohttp.TCPConnector(ssl=True)  # safe default\n    else:\n        raise","preventionTips":["Build ssl.SSLContext for custom CA bundles - never pass a path string as ssl.","Type-check config-derived ssl values before constructing the connector.","Treat None as 'use the sentinel', not a valid ssl value."],"tags":["connector","ssl","type-error","tcp-connector"],"backgroundTag":null,"analyzedSha":"d041d4d0fd48c3f0832084d33be16cf1c4835f85","analyzedAt":"2026-08-11T20:44:15.550Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}