Conversation
Per-request rejectUnauthorized/ca/servername were silently ignored when the https.Agent set the same option, because http.Agent merges request options over the agent's own, letting the agent win. Capture the per-request overrides and re-apply them in createConnection(), mirroring the checkServerIdentity handling from CVE-2026-58040. Refs: nodejs@52a8ace880d Signed-off-by: axedos <acceleratingssoul@proton.me>
|
Review requested:
|
|
Welcome to Node.js, and thank you for your first contribution! Before review, please take a moment to read:
Please make sure every commit is signed off. For a first pull request, GitHub Actions require collaborator approval and Jenkins CI must be started by a collaborator or triager, so an initial wait is normal. Caution AgentScan found account activity patterns that may be consistent with automation. This is a heuristic, not proof that this pull request was opened by an agent or violates policy. AI-assisted contributions are permitted, but automated tooling must not open pull requests without advance approval, and contributors must personally understand, test, verify, and take responsibility for every submitted change. See the AgentScan analysis, AI use policy, and automation policy for additional context. |
|
This is a resubmission of #66288. The change is the same, i just fixed the linting issue in the test files and rewrapped the commit message body just like the instructions said. I wrote and tested the original change myself but AI helped with identifying lint violations. Hope the PR helps i guess!! |
You should not need to resubmit a PR if you make changes. Please check the information in the rebase section of the Pull requests documentation and the section https://github.com/nodejs/node/blob/main/doc/contributing/pull-requests.md#step-9-discuss-and-update |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #66507 +/- ##
==========================================
+ Coverage 90.37% 90.42% +0.05%
==========================================
Files 790 790
Lines 273807 275478 +1671
Branches 52367 52844 +477
==========================================
+ Hits 247446 249110 +1664
+ Misses 16869 16768 -101
- Partials 9492 9600 +108
🚀 New features to boost your workflow:
|
Per-request
rejectUnauthorized/ca/servernamewere silentlyignored when the
https.Agentset the same option, becausehttp.Agentmerges request options over the agent's own,letting the agent win. Capture the per-request overrides
and re-apply them in
createConnection(), mirroring thecheckServerIdentityhandling from CVE-2026-58040.Refs: 52a8ace880d