I am deploying a Fastify api to digitalocean using a managed Postgres db and everything works fine in my local dev environment but i'm having issues when i deploy to my DO droplet. When starting the server i get an error stating: Failed to prune sessions: self signed certificate in certificate chain. From everything i can find it appears to be coming from pg-connect-simple, but i cant figure out how to safely get rid of the error. The ONLY way i can get it to work is by setting process.env.NODE_TLS_REJECT_UNAUTHORIZED = 0, but this is a security risk that i really don't want in production and node throws a warning stating that as well.
In dev i'm just using http but once in DO, its using https via letsencrypt with all http requests forwarded to https.
Any suggestions would be great on how to get this resolved safely and correctly.
session.js
const cookie = require('fastify-cookie');
const session = require('@fastify/session');
const csrf = require('fastify-csrf');
const pgSession = require('connect-pg-simple')(session);
const fp = require('fastify-plugin');
const plugin = async (fastify) => {
// All plugin data here is global to fastify.
fastify.register(cookie);
fastify.register(csrf, { sessionPlugin: 'fastify-session' });
fastify.register(session, {
store: new pgSession({
tableName: 'user_session', // Defaults to 'session'
}),
secret: process.env.SESSION_SECRET,
saveUninitialized: false,
cookie: {
httpOnly: true,
secure: process.env.NODE_ENV !== 'development',
maxAge: 86400 * 1000, // 1 day expiration time
},
});
// Add the user object to the session for later use.
fastify.addHook('preHandler', (req, reply, next) => {
if (!req.session) req.session.user = {};
next();
});
};
module.exports = fp(plugin);