Skip to content

Conversation

@krichprollsch
Copy link
Member

@krichprollsch krichprollsch commented Oct 21, 2025

In relation with #1160

I assume I can change CURLOPT_SSL_VERIFYHOST, CURLOPT_SSL_VERIFYPEER, CURLOPT_PROXY_SSL_VERIFYHOST and CURLOPT_PROXY_SSL_VERIFYPEER with active connections. Not sure if it's safe 🤔

@krichprollsch krichprollsch self-assigned this Oct 21, 2025
@krichprollsch krichprollsch force-pushed the cdp-security-ignore-cert-err branch from 810b04d to d2065f7 Compare October 21, 2025 11:44
@karlseguin
Copy link
Collaborator

I don't think it's safe...except for the fact that CDP generally does all of its setup before navigating to the page.

You could check if self.in_use.first != null and either log a message or reject the change.

@krichprollsch
Copy link
Member Author

PR updated

@krichprollsch krichprollsch merged commit fb6fbff into main Oct 21, 2025
10 checks passed
@krichprollsch krichprollsch deleted the cdp-security-ignore-cert-err branch October 21, 2025 13:15
@github-actions github-actions bot locked and limited conversation to collaborators Oct 21, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants