mssql: give TLS a host name when the server is an address
Node 25 refuses an IP address as the TLS server name, and the module reaches its server on loopback, so every connection failed on the live machines. The certificate is trusted either way.
This commit is contained in:
@@ -11,6 +11,7 @@
|
||||
// Structured rows still come back as JSON rendered by SQL Server itself (`FOR JSON`), so a tool's
|
||||
// answer is shaped exactly as it was: SQL Server owns the quoting and typing.
|
||||
|
||||
import { isIP } from "node:net";
|
||||
import { randomBytes } from "node:crypto";
|
||||
import { readFileSync } from "node:fs";
|
||||
import sql from "mssql";
|
||||
@@ -45,7 +46,10 @@ export const connectWithDriver: Connect = async (to) => {
|
||||
user: to.user,
|
||||
password: to.password,
|
||||
database: to.database,
|
||||
options: { encrypt: true, trustServerCertificate: true },
|
||||
// TLS names a host, never an address: Node refuses an IP as the server name (DEP0123, an error
|
||||
// since Node 25), and the module reaches its server on loopback. The certificate is trusted
|
||||
// either way, so the name only has to be one TLS accepts.
|
||||
options: { encrypt: true, trustServerCertificate: true, ...(isIP(to.host) ? { serverName: "localhost" } : {}) },
|
||||
pool: { min: 0, max: 1 },
|
||||
connectionTimeout: 15_000,
|
||||
requestTimeout: 60_000,
|
||||
|
||||
Vendored
+1
-1
@@ -18,7 +18,7 @@ declare module "mssql" {
|
||||
user?: string;
|
||||
password?: string;
|
||||
database?: string;
|
||||
options?: { encrypt?: boolean; trustServerCertificate?: boolean };
|
||||
options?: { encrypt?: boolean; trustServerCertificate?: boolean; serverName?: string };
|
||||
pool?: { min?: number; max?: number };
|
||||
connectionTimeout?: number;
|
||||
requestTimeout?: number;
|
||||
|
||||
Reference in New Issue
Block a user