From 6171d747db8a7525b46b2691f8c013c97d800cfa Mon Sep 17 00:00:00 2001 From: jochen Date: Sun, 4 Oct 2026 01:31:31 +0200 Subject: [PATCH] mssql: give TLS a host name when the server is an address Node 25 refuses an IP address as the TLS server name, and the module reaches its server on loopback, so every connection failed on the live machines. The certificate is trusted either way. --- modules/mssql/client.ts | 6 +++++- modules/mssql/mssql.d.ts | 2 +- 2 files changed, 6 insertions(+), 2 deletions(-) diff --git a/modules/mssql/client.ts b/modules/mssql/client.ts index a17998b..2fbb208 100644 --- a/modules/mssql/client.ts +++ b/modules/mssql/client.ts @@ -11,6 +11,7 @@ // Structured rows still come back as JSON rendered by SQL Server itself (`FOR JSON`), so a tool's // answer is shaped exactly as it was: SQL Server owns the quoting and typing. +import { isIP } from "node:net"; import { randomBytes } from "node:crypto"; import { readFileSync } from "node:fs"; import sql from "mssql"; @@ -45,7 +46,10 @@ export const connectWithDriver: Connect = async (to) => { user: to.user, password: to.password, database: to.database, - options: { encrypt: true, trustServerCertificate: true }, + // TLS names a host, never an address: Node refuses an IP as the server name (DEP0123, an error + // since Node 25), and the module reaches its server on loopback. The certificate is trusted + // either way, so the name only has to be one TLS accepts. + options: { encrypt: true, trustServerCertificate: true, ...(isIP(to.host) ? { serverName: "localhost" } : {}) }, pool: { min: 0, max: 1 }, connectionTimeout: 15_000, requestTimeout: 60_000, diff --git a/modules/mssql/mssql.d.ts b/modules/mssql/mssql.d.ts index d58a508..bcf3e41 100644 --- a/modules/mssql/mssql.d.ts +++ b/modules/mssql/mssql.d.ts @@ -18,7 +18,7 @@ declare module "mssql" { user?: string; password?: string; database?: string; - options?: { encrypt?: boolean; trustServerCertificate?: boolean }; + options?: { encrypt?: boolean; trustServerCertificate?: boolean; serverName?: string }; pool?: { min?: number; max?: number }; connectionTimeout?: number; requestTimeout?: number;