cloud_api_client: Use the platform TLS verifier for the cloud websocket (#63686)
# Objective
Fixes #63683
Behind a corporate TLS-inspecting proxy (e.g. Zscaler) whose root CA is
installed in the OS trust store, the Zed Cloud websocket fails
permanently with `invalid peer certificate: UnknownIssuer`, while every
other connection in Zed works.
`crates/cloud_api_client/src/websocket/native.rs` calls
`yawc::WebSocket::connect` without a TLS connector. yawc's default
connector trusts only the bundled `webpki-roots`, so it never consults
the platform trust store. Everything else in Zed (the reqwest HTTP
client and the collab websocket in `crates/client`) uses
`http_client_tls::tls_config()`, which is built on
`rustls-platform-verifier`.
## Solution
Pass a `tokio_rustls::TlsConnector` built from
`http_client_tls::tls_config()` to yawc via
`WebSocketBuilder::with_connector`, so the cloud websocket verifies
certificates exactly like the collab websocket does
(`client_async_tls_with_connector_and_config(...,
Some(Arc::new(http_client_tls::tls_config()).into()), ...)`).
`cloud_api_client` gains two non-wasm dependencies: `http_client_tls`
(workspace crate) and `tokio-rustls` (same `0.26` line yawc and `client`
already use, no default features).
🤖 Generated with [Claude Code](https://claude.com/claude-code)
https://claude.ai/code/session_01Ub1SNsrgWjTA6iAKanKfwt
## Testing
- `cargo check -p cloud_api_client` and `cargo fmt --check` on macOS
(arm64).
- Reproduced the bug and validated the approach with a standalone rustls
probe against `cloud.zed.dev` / `collab.zed.dev` from behind Zscaler:
- `webpki_roots::TLS_SERVER_ROOTS` only (yawc's default):
`InvalidCertificate(UnknownIssuer)` – identical to the error in the Zed
log
- `ClientConfig::with_platform_verifier()` (what `tls_config()`
returns): connects fine
- Reviewers behind a TLS-inspecting proxy can confirm by watching
`~/Library/Logs/Zed/Zed.log` for `cloud websocket connect failed:
invalid peer certificate: UnknownIssuer` before and after.
- I could not test on Windows or Linux, but the change only routes the
cloud websocket through the same `tls_config()` those platforms already
use for all other HTTPS traffic.
## Self-Review Checklist:
- [x] I've reviewed my own diff for quality, security, and reliability
- [x] Unsafe blocks (if any) have justifying comments
- [x] The content adheres to Zed's UI standards
([UX/UI](https://github.com/zed-industries/zed/blob/main/CONTRIBUTING.md#uiux-checklist)
and
[icon](https://github.com/zed-industries/zed/blob/main/crates/icons/README.md)
guidelines)
- [ ] Tests cover the new/changed behavior
- [x] Performance impact has been considered and is acceptable
Release Notes:
- Fixed the Zed Cloud connection failing with `UnknownIssuer` behind
corporate TLS-inspecting proxies whose root CA is installed in the
system trust store.
---------
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Co-authored-by: Finn Evers <finn@zed.dev>
12f79c0aebJoep Joosten committed on 9/29/2026, 10:23:00 AM· committed by GitHubparentc32938c