WebMock certificate validation bypass in RSpec unit tests
0 reputation · 22 Apr 2021, 15:50 UTC
When using RSpec with WebMock to intercept HTTP requests, the library intercepts calls at the library level. This mechanism typically bypasses the actual SSL/TLS handshake, meaning certificate validation logic is never executed. Developers need to verify how the application handles expired certificates, mismatched hostnames, or untrusted CAs.
There is currently no built-in DSL within RSpec or WebMock to simulate specific TLS chain failures or OpenSSL errors without relying on external process stubs. Stubbing a request returns a predefined response object, but the underlying client code responsible for verifying the server's identity remains untouched during the test suite execution.
What is the standard recommended approach for simulating an OpenSSL::SSLError within an RSpec test without spinning up a local Rack server? Can WebMock be configured to trigger a certificate-related failure natively during a stubbed request?