Skip to content

client-certificate-auth API Reference


client-certificate-auth API Reference / helpers / allowSAN

Function: allowSAN() ​

allowSAN(values): ValidationCallback

Defined in: helpers.js:254

Create a validation callback that allows certificates with matching Subject Alternative Names. Values may carry a type prefix ("DNS:api.example.com") or be bare, in which case they match that value under any SAN type. Type prefixes, DNS names, email addresses, and IP addresses compare case-insensitively; URIs fold only the scheme and host, so userinfo, path, query, and fragment stay case-sensitive. Values Node renders JSON-quoted (containing commas, quotes, or control characters) are decoded before comparison.

Parameters ​

values ​

string[]

Allowed SAN values (e.g., "DNS:example.com", "example.com", "user@example.com")

Returns ​

ValidationCallback

Example ​

ts
app.use(clientCertificateAuth(allowSAN(['DNS:api.example.com', 'email:admin@example.com'])));

Released under the MIT License.