信任自签名证书——Node.js与Aurelia请求代理问题
Let's break down what's going on here and fix this step by step:
Why Your Previous Attempts Failed
First, let's clear up why those approaches didn't work:
- The
process is not definederror happens becauseprocessis a Node.js global object — it doesn't exist in the browser environment where your Aurelia frontend runs. Putting that line in your frontend code will never work. - Setting system-wide environment variables might not have worked because either your terminal session didn't reload the variables (you need to restart the terminal after setting them) or your Aurelia startup script wasn't inheriting them correctly.
Recommended Solutions (From Safest to Quickest)
1. Configure Your Aurelia Proxy to Ignore Self-Signed Certificates (Best Practice)
Instead of disabling all TLS validation globally, just disable it for your specific proxy. This is way safer for development.
If you're using the Aurelia CLI, edit your aurelia_project/aurelia.json file and update your proxy configuration to include "secure": false:
"proxies": [ { "name": "backend-api", "url": "https://localhost:9443", "pattern": "/rest/open/*", "secure": false } ]
If you're using Webpack Dev Server directly, modify your webpack.config.js devServer proxy settings:
devServer: { proxy: { '/rest/open': { target: 'https://localhost:9443', secure: false, // Disables certificate validation for this proxy changeOrigin: true } } }
2. Set the Environment Variable When Starting Your Aurelia App
If you want a quick fix for development, pass the NODE_TLS_REJECT_UNAUTHORIZED=0 variable directly in your npm start script. This ensures the Node.js process running your proxy picks up the setting.
- Linux/macOS: Update your
package.jsonscripts:"scripts": { "start": "NODE_TLS_REJECT_UNAUTHORIZED=0 aurelia-cli run" } - Windows: Use
setto define the variable before running the command:"scripts": { "start": "set NODE_TLS_REJECT_UNAUTHORIZED=0 && aurelia-cli run" }
3. Add the Self-Signed Certificate to Node.js Trust Store (Most Secure for Long-Term Dev)
For a more robust dev setup, you can tell Node.js to trust your self-signed certificate instead of disabling validation entirely:
- Export your backend's self-signed certificate as a
.pemfile. - Set the
NODE_EXTRA_CA_CERTSenvironment variable to point to this file when starting your app:# Linux/macOS NODE_EXTRA_CA_CERTS=/path/to/your/cert.pem aurelia-cli run:: Windows set NODE_EXTRA_CA_CERTS=C:\path\to\your\cert.pem && aurelia-cli run
Important Note for Production
Never use NODE_TLS_REJECT_UNAUTHORIZED=0 in production. This disables critical security checks and leaves your app vulnerable. Always use a valid, CA-signed certificate in production environments.
内容的提问来源于stack exchange,提问作者Vijay Nandwana

