Skip to content

Enable WebID-TLS integration tests (fix self-signed cert verification loop) #1841

Description

@melvincarvalho

Summary

In October 2019, WebID-TLS tests were disabled with describe.skip() (commit 778095ad). The authentication code still works - just the tests are skipped and CI lacks DNS setup.

Fix size: ~10 lines changed.

The Bug

// Added Oct 29, 2019 by jaxoncreed
describe.skip('ACL with WebID+TLS', function () {  // <-- this .skip

The comment says "TLS is currently broken" but the code isn't broken - the tests just need tim.localhost to resolve to 127.0.0.1.

The Fix

1. Remove 5x .skip from test/integration/acl-tls-test.mjs:

  • Line 67, 134, 571, 616, 946

2. Add 4 lines to CI (.github/workflows/ci.yml):

- name: Setup hosts for TLS tests
  run: |
    echo "127.0.0.1 tim.localhost" | sudo tee -a /etc/hosts
    echo "127.0.0.1 nicola.localhost" | sudo tee -a /etc/hosts

Done.

Verification

The code works today:

  • Server starts with --auth tls ✅
  • Responds to requests ✅
  • Test certificates match test profiles ✅
  • cert:modulus in profile matches cert ✅

Why It Matters

  • README still advertises --auth tls support
  • Solid spec requires OIDC, doesn't forbid TLS
  • Server-to-server, CLI, IoT use cases need non-browser auth
  • W3C LWS working group discussing enterprise mTLS needs (LWS-UCS #40)

References

Activity

  1. added 2 commits that reference this issue on Jan 8, 2026
    410fd55
    b4f72c5
  2. melvincarvalho commented on Jan 8, 2026

    @melvincarvalho
    ContributorAuthor

    Investigation Results

    After deeper investigation and testing, the situation is:

    The Good News

    The WebID-TLS authentication code is functional and has been all along. The handlers at lib/api/authn/webid-tls.mjs and verification at lib/webid/lib/verify.mjs work correctly with real certificates.

    The Actual Issue

    The tests timeout due to a self-signed certificate verification loop:

    1. Test client connects with cert containing WebID https://tim.localhost:7777/profile/card#me
    2. Server's webid.verify() fetches that profile URL to verify the certificate
    3. Internal fetch() in lib/webid/lib/get.mjs rejects the self-signed cert
    4. Request hangs until timeout

    The NODE_TLS_REJECT_UNAUTHORIZED=0 env var only affects the test client, not the server's internal fetch calls.

    Updated PR

    Changed the PR scope to just document the actual issue rather than claim to "fix" it. The new documentation in the test file explains exactly what's happening and how to properly fix it.

    PR #1842 now just improves the documentation, replacing the misleading "TLS is broken" comment with accurate technical explanation.

  3. melvincarvalho commented on Jan 8, 2026

    @melvincarvalho
    ContributorAuthor

    Suggested Tests That Actually Work

    While the full integration tests remain blocked by the self-signed cert issue, here are tests that work today:

    Already Existing (unit tests with mocks)

    • test/unit/tls-authenticator-test.mjs - Tests TlsAuthenticator with mocked webid.verify()
    • test/unit/auth-handlers-test.mjs - Tests setAuthenticateHeader() for WebID-TLS

    Suggested Additional Unit Tests

    1. Test verifyKey() directly (no network needed)

    import { verifyKey } from '../../lib/webid/lib/verify.mjs'
    
    const certObj = {
      modulus: 'abc123...',
      exponent: '10001'
    }
    const profile = `
      @prefix cert: <http://www.w3.org/ns/auth/cert#> .
      <#me> cert:key [ cert:modulus "abc123..."^^xsd:hexBinary ; cert:exponent 65537 ] .
    `
    verifyKey(certObj, 'https://alice.example.com/profile/card#me', profile, 'text/turtle', (err, success) => {
      // assertions
    })

    2. Test URI extraction from certificate SAN

    // Test the internal getUris() logic
    const cert = { subjectaltname: 'URI:https://alice.example.com#me, URI:https://bob.example.com#me' }
    // Should extract both URIs

    3. Test handler with/without certificate

    // No cert → next() with empty session
    // Cert present → attempt verification (can mock webid.verify)

    These unit tests would provide good coverage of the WebID-TLS code paths without needing to solve the self-signed cert verification loop.

  4. changed the title [-]Bug: WebID-TLS tests disabled 5 years ago, ~10 line fix to re-enable[/-] [+]Enable WebID-TLS integration tests (fix self-signed cert verification loop)[/+] on Jan 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions