Node built in fetch dont reject unauthorized - How to handle self-signed certificates? or Why does no

20 Replies, 1641 Views

Hey folks,

So I just noticed that the node built in fetch dont reject unauthorized certs by default? Like, it just happily connects to servers with self-signed or invalid certs.

Isn’t that kinda risky? Or am I missing something?

I get that it might be for dev convenience, but how do I *enforce* strict cert checks? I don’t wanna accidentally ignore security issues in prod.

Also, is there a way to *disable* this behavior if I *do* wanna reject unauthorized certs? Tried googling but couldn’t find a straight answer.

Thanks in advance!

(Also, why isn’t this more clearly documented? Feels like a gotcha waiting to happen.)

Messages In This Thread
Node built in fetch dont reject unauthorized - How to handle self-signed certificates? or Why does no - by - 17-06-2024, 06:41 AM



Users browsing this thread: 1 Guest(s)