Hey folks,
So I just noticed that the node built in fetch dont reject unauthorized certs by default? Like, it just happily connects to servers with self-signed or invalid certs.
Isn’t that kinda risky? Or am I missing something?
I get that it might be for dev convenience, but how do I *enforce* strict cert checks? I don’t wanna accidentally ignore security issues in prod.
Also, is there a way to *disable* this behavior if I *do* wanna reject unauthorized certs? Tried googling but couldn’t find a straight answer.
Thanks in advance!
(Also, why isn’t this more clearly documented? Feels like a gotcha waiting to happen.)
So I just noticed that the node built in fetch dont reject unauthorized certs by default? Like, it just happily connects to servers with self-signed or invalid certs.
Isn’t that kinda risky? Or am I missing something?
I get that it might be for dev convenience, but how do I *enforce* strict cert checks? I don’t wanna accidentally ignore security issues in prod.
Also, is there a way to *disable* this behavior if I *do* wanna reject unauthorized certs? Tried googling but couldn’t find a straight answer.
Thanks in advance!
(Also, why isn’t this more clearly documented? Feels like a gotcha waiting to happen.)
