Add WebSocketClient::enable_server_hostname_verification

WebSocketClient's TLS setup already threaded
ClientTlsSessionOptions::server_hostname_verification through
setup_client_tls_session(), the same path SSLClient uses, but never
exposed a way to set it: create_stream() called setup_client_tls_session()
without an options argument, so the default (verification on) was the
only reachable value.

Add the public setter, mirroring ClientImpl/SSLClient/Client, and wire
it into create_stream()'s ClientTlsSessionOptions. Last open item from
issue #2531's WebSocketClient/SSLClient API alignment.
This commit is contained in:
yhirose
2026-08-07 18:48:59 -04:00
parent 6018c7feb3
commit 86d0210391
3 changed files with 34 additions and 5 deletions
+17
View File
@@ -21123,6 +21123,23 @@ TEST_F(WebSocketSSLDnsHostTest, TrustedChainWrongNameFails) {
EXPECT_EQ(-1, res.status());
}
// Same setup as TrustedChainWrongNameFails, but with hostname verification
// disabled: the chain is still checked, only the identity check is skipped
TEST_F(WebSocketSSLDnsHostTest, HostnameVerificationDisabledAcceptsWrongName) {
Start(SERVER_CERT_FILE);
ws::WebSocketClient client(url());
client.set_ca_cert_path(SERVER_CERT_FILE);
client.enable_server_hostname_verification(false);
ASSERT_TRUE(client.connect());
ASSERT_TRUE(client.send("hello"));
std::string msg;
EXPECT_EQ(ws::Text, client.read(msg));
EXPECT_EQ("hello", msg);
client.close();
}
// A CA that did not sign the server certificate fails the chain, even though
// the name would match
TEST_F(WebSocketSSLDnsHostTest, UntrustedChainFails) {