mssql: give TLS a host name when the server is an address

Node 25 refuses an IP address as the TLS server name, and the module reaches its server on
loopback, so every connection failed on the live machines. The certificate is trusted either way.
This commit is contained in:
jochen
2026-10-04 01:31:31 +02:00
parent 84609c0373
commit 6171d747db
2 changed files with 6 additions and 2 deletions
+5 -1
View File
@@ -11,6 +11,7 @@
// Structured rows still come back as JSON rendered by SQL Server itself (`FOR JSON`), so a tool's // Structured rows still come back as JSON rendered by SQL Server itself (`FOR JSON`), so a tool's
// answer is shaped exactly as it was: SQL Server owns the quoting and typing. // answer is shaped exactly as it was: SQL Server owns the quoting and typing.
import { isIP } from "node:net";
import { randomBytes } from "node:crypto"; import { randomBytes } from "node:crypto";
import { readFileSync } from "node:fs"; import { readFileSync } from "node:fs";
import sql from "mssql"; import sql from "mssql";
@@ -45,7 +46,10 @@ export const connectWithDriver: Connect = async (to) => {
user: to.user, user: to.user,
password: to.password, password: to.password,
database: to.database, database: to.database,
options: { encrypt: true, trustServerCertificate: true }, // TLS names a host, never an address: Node refuses an IP as the server name (DEP0123, an error
// since Node 25), and the module reaches its server on loopback. The certificate is trusted
// either way, so the name only has to be one TLS accepts.
options: { encrypt: true, trustServerCertificate: true, ...(isIP(to.host) ? { serverName: "localhost" } : {}) },
pool: { min: 0, max: 1 }, pool: { min: 0, max: 1 },
connectionTimeout: 15_000, connectionTimeout: 15_000,
requestTimeout: 60_000, requestTimeout: 60_000,
+1 -1
View File
@@ -18,7 +18,7 @@ declare module "mssql" {
user?: string; user?: string;
password?: string; password?: string;
database?: string; database?: string;
options?: { encrypt?: boolean; trustServerCertificate?: boolean }; options?: { encrypt?: boolean; trustServerCertificate?: boolean; serverName?: string };
pool?: { min?: number; max?: number }; pool?: { min?: number; max?: number };
connectionTimeout?: number; connectionTimeout?: number;
requestTimeout?: number; requestTimeout?: number;