Repository navigation
Enable WebID-TLS integration tests (fix self-signed cert verification loop) #1841
Description
Activity
- added 2 commits that reference this issue
on Jan 8, 2026 Investigation Results
After deeper investigation and testing, the situation is:
The Good News
The WebID-TLS authentication code is functional and has been all along. The handlers at
lib/api/authn/webid-tls.mjsand verification atlib/webid/lib/verify.mjswork correctly with real certificates.The Actual Issue
The tests timeout due to a self-signed certificate verification loop:
- Test client connects with cert containing WebID
https://tim.localhost:7777/profile/card#me - Server's
webid.verify()fetches that profile URL to verify the certificate - Internal
fetch()inlib/webid/lib/get.mjsrejects the self-signed cert - Request hangs until timeout
The
NODE_TLS_REJECT_UNAUTHORIZED=0env var only affects the test client, not the server's internal fetch calls.Updated PR
Changed the PR scope to just document the actual issue rather than claim to "fix" it. The new documentation in the test file explains exactly what's happening and how to properly fix it.
PR #1842 now just improves the documentation, replacing the misleading "TLS is broken" comment with accurate technical explanation.
- Test client connects with cert containing WebID
- added a commit that references this issue
on Jan 8, 2026 Suggested Tests That Actually Work
While the full integration tests remain blocked by the self-signed cert issue, here are tests that work today:
Already Existing (unit tests with mocks)
test/unit/tls-authenticator-test.mjs- TestsTlsAuthenticatorwith mockedwebid.verify()test/unit/auth-handlers-test.mjs- TestssetAuthenticateHeader()for WebID-TLS
Suggested Additional Unit Tests
1. Test
verifyKey()directly (no network needed)import { verifyKey } from '../../lib/webid/lib/verify.mjs' const certObj = { modulus: 'abc123...', exponent: '10001' } const profile = ` @prefix cert: <http://www.w3.org/ns/auth/cert#> . <#me> cert:key [ cert:modulus "abc123..."^^xsd:hexBinary ; cert:exponent 65537 ] . ` verifyKey(certObj, 'https://alice.example.com/profile/card#me', profile, 'text/turtle', (err, success) => { // assertions })
2. Test URI extraction from certificate SAN
// Test the internal getUris() logic const cert = { subjectaltname: 'URI:https://alice.example.com#me, URI:https://bob.example.com#me' } // Should extract both URIs
3. Test handler with/without certificate
// No cert → next() with empty session // Cert present → attempt verification (can mock webid.verify)
These unit tests would provide good coverage of the WebID-TLS code paths without needing to solve the self-signed cert verification loop.
- added 2 commits that reference this issue
on Jan 8, 2026 - changed the title
[-]Bug: WebID-TLS tests disabled 5 years ago, ~10 line fix to re-enable[/-][+]Enable WebID-TLS integration tests (fix self-signed cert verification loop)[/+]on Jan 8, 2026
Summary
In October 2019, WebID-TLS tests were disabled with
describe.skip()(commit778095ad). The authentication code still works - just the tests are skipped and CI lacks DNS setup.Fix size: ~10 lines changed.
The Bug
The comment says "TLS is currently broken" but the code isn't broken - the tests just need
tim.localhostto resolve to127.0.0.1.The Fix
1. Remove 5x
.skipfromtest/integration/acl-tls-test.mjs:2. Add 4 lines to CI (
.github/workflows/ci.yml):Done.
Verification
The code works today:
--auth tls✅cert:modulusin profile matches cert ✅Why It Matters
--auth tlssupportReferences
778095ad(Oct 29, 2019)