Skip to content

https: honor per-request TLS options over agent options - #66507

Open
axedos wants to merge 1 commit into
nodejs:mainfrom
axedos:https-per-request-tls-override
Open

axedos wants to merge 1 commit into
nodejs:mainfrom
axedos:https-per-request-tls-override

Conversation

@axedos

@axedos axedos commented Oct 4, 2026

Copy link
Copy Markdown

Per-request rejectUnauthorized/ca/servername were silently
ignored when the https.Agent set the same option, because
http.Agent merges request options over the agent's own,
letting the agent win. Capture the per-request overrides
and re-apply them in createConnection(), mirroring the
checkServerIdentity handling from CVE-2026-58040.

Refs: 52a8ace880d

Per-request rejectUnauthorized/ca/servername were silently
ignored when the https.Agent set the same option, because
http.Agent merges request options over the agent's own,
letting the agent win. Capture the per-request overrides
and re-apply them in createConnection(), mirroring the
checkServerIdentity handling from CVE-2026-58040.

Refs: nodejs@52a8ace880d
Signed-off-by: axedos <acceleratingssoul@proton.me>
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/crypto
  • @nodejs/http
  • @nodejs/net

@nodejs-github-bot nodejs-github-bot added https Issues and PRs related to the https subsystem. needs-ci PRs that need a full CI run. labels Oct 4, 2026
@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

Welcome to Node.js, and thank you for your first contribution!

Before review, please take a moment to read:

Please make sure every commit is signed off. For a first pull request, GitHub Actions require collaborator approval and Jenkins CI must be started by a collaborator or triager, so an initial wait is normal.

Caution

AgentScan found account activity patterns that may be consistent with automation. This is a heuristic, not proof that this pull request was opened by an agent or violates policy. AI-assisted contributions are permitted, but automated tooling must not open pull requests without advance approval, and contributors must personally understand, test, verify, and take responsibility for every submitted change. See the AgentScan analysis, AI use policy, and automation policy for additional context.

@axedos

axedos commented Oct 4, 2026

Copy link
Copy Markdown
Author

This is a resubmission of #66288. The change is the same, i just fixed the linting issue in the test files and rewrapped the commit message body just like the instructions said. I wrote and tested the original change myself but AI helped with identifying lint violations. Hope the PR helps i guess!!

@MikeMcC399

Copy link
Copy Markdown
Contributor

This is a resubmission of #66288. The change is the same, i just fixed the linting issue in the test files and rewrapped the commit message body just like the instructions said. I wrote and tested the original change myself but AI helped with identifying lint violations. Hope the PR helps i guess!!

You should not need to resubmit a PR if you make changes. Please check the information in the rebase section of the Pull requests documentation and the section https://github.com/nodejs/node/blob/main/doc/contributing/pull-requests.md#step-9-discuss-and-update

@codecov

codecov Bot commented Oct 4, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 90.42%. Comparing base (bc6e1ad) to head (cf03ae0).
⚠️ Report is 172 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff             @@
##             main   #66507      +/-   ##
==========================================
+ Coverage   90.37%   90.42%   +0.05%     
==========================================
  Files         790      790              
  Lines      273807   275478    +1671     
  Branches    52367    52844     +477     
==========================================
+ Hits       247446   249110    +1664     
+ Misses      16869    16768     -101     
- Partials     9492     9600     +108     
Files with missing lines Coverage Δ
lib/https.js 98.11% <100.00%> (+0.90%) ⬆️

... and 138 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

icecold009

This comment was marked as low quality.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

agentscan:mixed-signals https Issues and PRs related to the https subsystem. needs-ci PRs that need a full CI run.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants