node/test/parallel/test-quic-datagram.mjs
James M Snell 430f89eb8d quic: improve peer cert verification
On the client, add verifyPeer: 'auto', 'strict', and
'manual' modes. The 'strict' mode will reject invalid
certs at the handshake layer, while the 'manual' mode
allows the application to inspect the peer cert and decide
whether to trust it or not. The 'auto' mode is the default
and will reject invalid certs at a middle layer after the
onhandshake event.

Signed-off-by: James M Snell <jasnell@gmail.com>
Assisted-by: Opencode/Opus 4.6
PR-URL: https://github.com/nodejs/node/pull/63483
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
2026-05-24 19:14:10 -07:00

63 lines
1.9 KiB
JavaScript

// Flags: --experimental-quic --no-warnings
// Test: basic datagram send and receive.
// Client sends datagram, server receives via ondatagram.
// maxDatagramSize reflects peer's transport param.
import { hasQuic, skip, mustCall } from '../common/index.mjs';
import assert from 'node:assert';
import * as fixtures from '../common/fixtures.mjs';
const { ok, strictEqual } = assert;
const { readKey } = fixtures;
if (!hasQuic) {
skip('QUIC is not enabled');
}
const { listen, connect } = await import('node:quic');
const { createPrivateKey } = await import('node:crypto');
const key = createPrivateKey(readKey('agent1-key.pem'));
const cert = readKey('agent1-cert.pem');
const serverGot = Promise.withResolvers();
const serverEndpoint = await listen(mustCall(async (serverSession) => {
await serverSession.opened;
// maxDatagramSize reflects peer's max payload (frame size
// minus DATAGRAM frame overhead of type byte + varint length).
ok(serverSession.maxDatagramSize > 0);
ok(serverSession.maxDatagramSize < 1200);
// Wait for the datagram before closing.
await serverGot.promise;
await serverSession.close();
}), {
sni: { '*': { keys: [key], certs: [cert] } },
alpn: ['quic-test'],
transportParams: { maxDatagramFrameSize: 1200 },
ondatagram: mustCall((data) => {
ok(data instanceof Uint8Array);
strictEqual(data.byteLength, 3);
serverGot.resolve();
}),
});
const clientSession = await connect(serverEndpoint.address, {
alpn: 'quic-test',
verifyPeer: 'manual',
transportParams: { maxDatagramFrameSize: 1200 },
});
await clientSession.opened;
// Client maxDatagramSize reflects actual payload max.
ok(clientSession.maxDatagramSize > 0);
ok(clientSession.maxDatagramSize < 1200);
// Client sends datagram.
const id = await clientSession.sendDatagram(new Uint8Array([1, 2, 3]));
assert.strictEqual(id, 1n);
await Promise.all([serverGot.promise, clientSession.closed]);
await serverEndpoint.close();