Skip to content

fix(tls): prevent crash when altNames in cert are not strings#26

Open
NikosRig wants to merge 1 commit into
sannysoft:masterfrom
NikosRig:fix/tls-altname-type-guard
Open

fix(tls): prevent crash when altNames in cert are not strings#26
NikosRig wants to merge 1 commit into
sannysoft:masterfrom
NikosRig:fix/tls-altname-type-guard

Conversation

@NikosRig

Copy link
Copy Markdown

🐛 Fix: TypeError in isMappingHostName for non-string DNS names

Description
This PR resolves a runtime error that occurs when the subjectAltName entries in a TLS certificate are objects instead of plain strings. The isMappingHostName() function was calling .replace() on these objects, leading to the following error:

TypeError: DNSName.replace is not a function

Changes
Added type checking in isMappingHostName() to extract .value safely and ensure it's a string before calling .replace().
Improved getMappingHostNamesFormCert() to filter and include only valid string values from altNames.
Why it matters
Without this fix, certain certificates cause the proxy to crash when intercepting HTTPS traffic due to incorrect handling of DNSName types in certificates.

How to test
Run the proxy server with SSL MITM enabled.
Visit a site with multiple or wildcard SANs in its cert.
Confirm no crash occurs and the traffic is intercepted correctly.

Guarded against non-string values in `isMappingHostName()` by extracting `.value` and validating type before using `.replace()`. Also updated `getMappingHostNamesFormCert()` to safely extract altNames.

Fixes `TypeError: DNSName.replace is not a function` caused by altNames being objects instead of strings.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant