You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在FHIRKit Client模块中禁用SSL验证

FHIRKit Client 连接自签名证书FHIR服务器的SSL验证问题解决方案

问题根源

Node.js v22 默认采用 undici 作为 fetch API的底层实现,而FHIRKit Client的新版本依赖该实现发起请求。你之前尝试的https.Agent配置仅适用于传统Node.js HTTP客户端,对基于undici的请求无效,因此触发UNABLE_TO_VERIFY_LEAF_SIGNATURE错误。


方法一:开发环境临时跳过SSL验证

通过配置FHIRKit Client的fetchOptions,传入undici的Agent并关闭证书验证:

const { Client } = require('fhir-kit-client');
const undici = require('undici');

const options = {
  baseUrl: 'https://localhost/fhir/r4/',
  customHeaders: {
    'content-type': 'application/fhir+json',
    'prefer': 'return=representation'
  },
  fetchOptions: {
    dispatcher: new undici.Agent({
      connect: {
        rejectUnauthorized: false
      }
    })
  }
};

const fhirClient = new Client(options);

搜索代码保持不变:

const searchResponse = await fhirClient.resourceSearch({
  resourceType: 'Patient',
  searchParams: { gender: 'female' }
});

⚠️ 注意:此方法仅用于本地开发测试,生产环境严禁使用,会导致SSL连接失去安全保障。


方法二:生产环境信任自签名证书

将服务器的自签名证书添加到客户端信任列表,既保证安全又能正常连接:

  1. 将服务器的自签名证书保存为本地文件(例如server-cert.pem)
  2. 修改FHIRKit Client配置,加载指定证书并开启验证:
const { Client } = require('fhir-kit-client');
const fs = require('fs');
const undici = require('undici');

const options = {
  baseUrl: 'https://localhost/fhir/r4/',
  customHeaders: {
    'content-type': 'application/fhir+json',
    'prefer': 'return=representation'
  },
  fetchOptions: {
    dispatcher: new undici.Agent({
      connect: {
        ca: fs.readFileSync('./server-cert.pem'), // 加载本地自签名证书
        rejectUnauthorized: true // 保持SSL验证开启,仅信任指定证书
      }
    })
  }
};

const fhirClient = new Client(options);

验证配置

重新运行搜索代码,若不再出现SSL相关错误,则配置生效。若仍有问题,检查证书文件路径是否正确,或确认证书与服务器当前使用的证书一致。

内容的提问来源于stack exchange,提问作者MrWalterWhite

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 04:52:03