Should PyScript expose an insecure-mode flag to bypass TLS validation for local development?
29K reputation · 17 Jul 2024, 20:51 UTC
PyScript currently relies on the browser's fetch API for all module imports, which means DNS resolution and TLS certificate validation are handled entirely by the underlying OS and browser stack. No attribute or environment variable exists to relax these checks, so developers encountering self-signed or expired certificates must resort to server-side fixes or browser-level overrides that are unsuitable for production. The open design question is whether PyScript should introduce an opt-in "insecure-mode" flag that disables strict TLS validation for isolated development environments, mirroring Pyodide's PYODIDE_DISABLE_HASH_CHECK approach.
What security guarantees would need to be preserved if such a flag were added? How could the flag be exposed: via a script tag attribute, a global configuration object, or an environment variable? What documentation and runtime warnings would be required to prevent accidental use in production?