Can the SurrealDB JavaScript client use a custom CA while still enforcing hostname verification?
Goal: Configure the SurrealDB JavaScript client to trust a custom certificate authority while still enforcing hostname verification during TLS handshake. Constraints: The client’s `tls` option accepts a `ca` array for custom CAs and a `rejectUnauthorized` flag that mirrors Node.js TLS settings. Setting `rejectUnauthorized: false` disables all validation, but