mirror of
https://github.com/yhirose/cpp-httplib.git
synced 2026-10-02 21:43:27 +07:00
ci: add best-effort BoringSSL job (#2456)
Adds Ubuntu and macOS CI jobs that build BoringSSL from source and exercise cpp-httplib's existing OpenSSL backend path (continue-on-error: best-effort). Makes SSLClientServerTest.TlsVerifyHostname backend-aware (BoringSSL is SAN-only per RFC 6125 §6.4.4). README notes BoringSSL as a best-effort variant with the C++14 and SAN-only caveats.
This commit is contained in:
@@ -10673,8 +10673,20 @@ TEST(SSLClientServerTest, TlsVerifyHostname) {
|
||||
<< "Verify callback should have been called";
|
||||
|
||||
// CN="Common Name" should match our test certificate
|
||||
//
|
||||
// BoringSSL intentionally drops CN-based hostname matching per RFC 6125
|
||||
// §6.4.4 — only SubjectAltName is consulted. Other backends (OpenSSL,
|
||||
// MbedTLS, wolfSSL) still honor the CN fallback, so flip the expectation
|
||||
// for BoringSSL builds. OPENSSL_IS_BORINGSSL is defined by BoringSSL's
|
||||
// <openssl/base.h>, which is included transitively when
|
||||
// CPPHTTPLIB_OPENSSL_SUPPORT is set against a BoringSSL install.
|
||||
#if defined(OPENSSL_IS_BORINGSSL)
|
||||
EXPECT_FALSE(verify_result_cn)
|
||||
<< "BoringSSL should reject CN-based hostname matching (SAN-only)";
|
||||
#else
|
||||
EXPECT_TRUE(verify_result_cn)
|
||||
<< "verify_hostname should match 'Common Name' (certificate CN)";
|
||||
#endif
|
||||
|
||||
// Wrong hostname should not match
|
||||
EXPECT_FALSE(verify_result_wrong)
|
||||
|
||||
Reference in New Issue
Block a user