Optionaloptions: OPCUAServerOptionsProtected Optional_Per-host "is this host covered by the certificate" verdicts backing _warnIfEndpointHostNotInCertificate(), keyed by the lower-cased host. Covers both outcomes so a correctly covered host is never rechecked either. Left undefined until first used: tests build a server with Object.create(OPCUABaseServer.prototype), which skips the constructor.
Protected Optional_The certificate (compared by reference) that _endpointHostCertificateCache was computed against. Every certificate provider in this codebase hands back the same Buffer instance from getCertificate() until it is invalidated, so a reference change reliably signals a new certificate and resets the cache.
Protected_false if anonymous connection are not allowed
the maximum number for concurrent connection per end point
ReadonlyoptionsOptionalregisterAdditional role resolvers (OPC 10000-18 §4.4). Packages like node-opcua-role-set-server push resolvers here.
true: CreateSessionResponse.serverCertificate carries the whole chain; false: the leaf certificate only. Read at each CreateSession.
Readonlyserverhow a remote Session's permission is resolved when no RolePermissions apply.
the user manager
StaticdefaultStaticdeprecated_the maximum number of subscription that can be created per server
StaticfallbackStaticmakeconstruct a service Fault response
StaticregistryStaticrequestif requestExactEndpointUrl is set to true the server will only accept createSession that have a endpointUrl that strictly matches one of the provided endpoint. This mean that if the server expose a endpoint with url such as opc.tcp://MYHOSTNAME:1234, client will not be able to reach the server with the ip address of the server. requestExactEndpointUrl = true => emulates the Prosys Server behavior requestExactEndpointUrl = false => emulates the Unified Automation behavior.
The server build info
total number of bytes read by the server since startup
total number of bytes written by the server since startup
File path of the certificate (or "<in-memory>").
the number of connected channel on all existing end points
the number of sessions currently active
The number of active subscriptions from all sessions
true if the server has been initialized
is the server auditing ?
the maximum number of concurrent sessions allowed on the server
File path of the private key (or "<in-memory>").
the publishing interval count
the number of request that have been rejected
the number of session activation requests that have been rejected
The type of server
the number of sessions that have been aborted
Number of transactions processed by the server since startup
Protected_Protected_Protected_Protected_Protected_Thin wrapper around findEndpointHostMissingFromCertificate() (the exploreCertificate() ASN.1 parse), extracted so tests can spy on how many times the expensive check actually runs when _warnIfEndpointHostNotInCertificate() caches its verdicts.
Protected_Protected_Protected_Protected_Protected_Protected_Protected_Protected_Protected_Protected_Protected_Protected_Protected_Protected_Protected_Protected_Protected_Protected_Protected_Protected_Protected_Protected_Protected_Protected_Protected_Protected_Protected_Protected_Protected_Protected_Warn once per host when a Client reaches this server through a host name that the server certificate does not cover (see findEndpointHostMissingFromCertificate() for the spec reference). Called from the GetEndpoints and CreateSession request paths, both reachable before any Session exists.
OPC 10000-4 v1.05.07 5.5.4.1 (GetEndpoints): "the Server should minimize the amount of processing required to send the response for this Service." GetEndpoints is unauthenticated, so a host, once checked against the current certificate, is never rechecked, whether it turned out covered or missing, and the number of distinct hosts remembered (MAX_CACHED_HOSTS) and warned about (MAX_WARNED_HOSTS) are both capped so an attacker sending arbitrarily many host names cannot grow the cache or the log without bound. The cache is reset when the certificate itself changes (e.g. after regenerateSelfSignedCertificate()), so a still-missing host is warned about once more.
Never throws: a failure here must not change the response sent to the Client.
Optional[captureThe Symbol.for('nodejs.rejection') method is called in case a
promise rejection happens when emitting an event and
captureRejections is enabled on the emitter.
It is possible to use events.captureRejectionSymbol in
place of Symbol.for('nodejs.rejection').
import { EventEmitter, captureRejectionSymbol } from 'node:events';
class MyClass extends EventEmitter {
constructor() {
super({ captureRejections: true });
}
[captureRejectionSymbol](err, event, ...args) {
console.log('rejection happened for', event, 'with', err, ...args);
this.destroy(err);
}
destroy(err) {
// Tear the resource down here.
}
}
Alias for emitter.on(eventName, listener).
Compare the current certificate's SAN entries against all explicitly configured hostnames and IPs, and return any that are missing.
Returns an empty array when the certificate covers every configured hostname and IP.
Important — ephemeral IP mitigation:
Auto-detected IPs (from getIpAddresses()) are deliberately
NOT included in this check. Network interfaces are transient
— WiFi IPs change on reconnect, tethering IPs appear/disappear,
VPN adapters come and go. Including them would cause the
[NODE-OPCUA-W26] warning to fire on every server restart
whenever the network state differs from when the certificate
was originally created.
Only explicitly configured values are checked:
alternateHostname (non-IP),
hostnames from advertisedEndpoints URLsalternateHostname, IP literals
from advertisedEndpoints URLsThe certificate itself still includes auto-detected IPs at creation time — this is fine because it captures the network state at that moment. But the mismatch warning only fires for things the user explicitly asked for.
Synchronously calls each of the listeners registered for the event named
eventName, in the order they were registered, passing the supplied arguments
to each.
Returns true if the event had listeners, false otherwise.
import { EventEmitter } from 'node:events';
const myEmitter = new EventEmitter();
// First listener
myEmitter.on('event', function firstListener() {
console.log('Helloooo! first listener');
});
// Second listener
myEmitter.on('event', function secondListener(arg1, arg2) {
console.log(`event with parameters ${arg1}, ${arg2} in second listener`);
});
// Third listener
myEmitter.on('event', function thirdListener(...args) {
const parameters = args.join(', ');
console.log(`event with parameters ${parameters} in third listener`);
});
console.log(myEmitter.listeners('event'));
myEmitter.emit('event', 1, 2, 3, 4, 5);
// Prints:
// [
// [Function: firstListener],
// [Function: secondListener],
// [Function: thirdListener]
// ]
// Helloooo! first listener
// event with parameters 1, 2 in second listener
// event with parameters 1, 2, 3, 4, 5 in third listener
Returns an array listing the events for which the emitter has registered listeners.
import { EventEmitter } from 'node:events';
const myEE = new EventEmitter();
myEE.on('foo', () => {});
myEE.on('bar', () => {});
const sym = Symbol('symbol');
myEE.on(sym, () => {});
console.log(myEE.eventNames());
// Prints: [ 'foo', 'bar', Symbol(symbol) ]
Same as getProvider, but guarantees invalidate() is present
— wrapping with a no-op if the current provider doesn't implement it
— for callers, such as OPCUAServerEndPoint.setCertificateProvider(),
that require the stricter ICertificateChainProvider shape.
Every call delegates live to whatever provider is current at call
time; it does not track later setProvider() swaps.
Protectedgetreturns a array of currently active channels
get one of the possible endpointUrl
Read the current value of
ServerConfiguration.InApplicationSetup.
The private key as an opaque sign/decrypt object, whatever the provider: an ICertificateKeyPairProvider2 answers directly (the only usable path when the key is HSM/KMS-held), any other provider gets its raw key wrapped. See getKeyOperationsFromProvider.
The raw private key.
prefer getKeyOperations: it works whether the key
is local or HSM/KMS-held, while this throws
PrivateKeyUnavailableError when the installed provider is opaque.
Kept for compatibility with code that genuinely needs key material
(e.g. push certificate management).
Return the current provider, e.g. so a caller can install the exact same provider instance elsewhere (endpoints reusing the server's resolved private-key provider rather than each re-resolving it).
Read the current ServerState from the
internal server status.
Initialize the server by installing default node set.
and instruct the server to listen to its endpoints.
const server = new OPCUAServer();
await server.initialize();
// default server namespace is now initialized
// it is a good time to create life instance objects
const namespace = server.engine.addressSpace.getOwnNamespace();
namespace.addObject({
browseName: "SomeObject",
organizedBy: server.engine.addressSpace.rootFolder.objects
});
// the addressSpace is now complete
// let's now start listening to clients
await server.start();
Initialize the server by installing default node set.
and instruct the server to listen to its endpoints.
const server = new OPCUAServer();
await server.initialize();
// default server namespace is now initialized
// it is a good time to create life instance objects
const namespace = server.engine.addressSpace.getOwnNamespace();
namespace.addObject({
browseName: "SomeObject",
organizedBy: server.engine.addressSpace.rootFolder.objects
});
// the addressSpace is now complete
// let's now start listening to clients
await server.start();
Invalidate cached certificate chain and private key so the next
getCertificate() / getPrivateKey() call re-reads from the
underlying source. For in-memory providers, this is a no-op.
ProtectedisProtectedisReturns the number of listeners listening for the event named eventName.
If listener is provided, it will return how many times the listener is found
in the list of the listeners of the event.
The name of the event being listened for
Optionallistener: (The event handler function
Returns a copy of the array of listeners for the event named eventName.
server.on('connection', (stream) => {
console.log('someone connected!');
});
console.log(util.inspect(server.listeners('connection')));
// Prints: [ [Function] ]
ProtectedmakeAlias for emitter.removeListener().
Adds the listener function to the end of the listeners array for the
event named eventName. No checks are made to see if the listener has
already been added. Multiple calls passing the same combination of eventName
and listener will result in the listener being added, and called, multiple
times.
server.on('connection', (stream) => {
console.log('someone connected!');
});
Returns a reference to the EventEmitter, so that calls can be chained.
By default, event listeners are invoked in the order they are added. The
emitter.prependListener() method can be used as an alternative to add the
event listener to the beginning of the listeners array.
import { EventEmitter } from 'node:events';
const myEE = new EventEmitter();
myEE.on('foo', () => console.log('a'));
myEE.prependListener('foo', () => console.log('b'));
myEE.emit('foo');
// Prints:
// b
// a
The name of the event.
The callback function
Adds a one-time listener function for the event named eventName. The
next time eventName is triggered, this listener is removed and then invoked.
server.once('connection', (stream) => {
console.log('Ah, we have our first user!');
});
Returns a reference to the EventEmitter, so that calls can be chained.
By default, event listeners are invoked in the order they are added. The
emitter.prependOnceListener() method can be used as an alternative to add the
event listener to the beginning of the listeners array.
import { EventEmitter } from 'node:events';
const myEE = new EventEmitter();
myEE.once('foo', () => console.log('a'));
myEE.prependOnceListener('foo', () => console.log('b'));
myEE.emit('foo');
// Prints:
// b
// a
The name of the event.
The callback function
ProtectedperformProtectedprepareAdds the listener function to the beginning of the listeners array for the
event named eventName. No checks are made to see if the listener has
already been added. Multiple calls passing the same combination of eventName
and listener will result in the listener being added, and called, multiple
times.
server.prependListener('connection', (stream) => {
console.log('someone connected!');
});
Returns a reference to the EventEmitter, so that calls can be chained.
The name of the event.
The callback function
Adds a one-time listener function for the event named eventName to the
beginning of the listeners array. The next time eventName is triggered, this
listener is removed, and then invoked.
server.prependOnceListener('connection', (stream) => {
console.log('Ah, we have our first user!');
});
Returns a reference to the EventEmitter, so that calls can be chained.
The name of the event.
The callback function
Returns a copy of the array of listeners for the event named eventName,
including any wrappers (such as those created by .once()).
import { EventEmitter } from 'node:events';
const emitter = new EventEmitter();
emitter.once('log', () => console.log('log once'));
// Returns a new Array with a function `onceWrapper` which has a property
// `listener` which contains the original listener bound above
const listeners = emitter.rawListeners('log');
const logFnWrapper = listeners[0];
// Logs "log once" to the console and does not unbind the `once` event
logFnWrapper.listener();
// Logs "log once" to the console and removes the listener
logFnWrapper();
emitter.on('log', () => console.log('log persistently'));
// Will return a new Array with a single function bound by `.on()` above
const newListeners = emitter.rawListeners('log');
// Logs "log persistently" twice
newListeners[0]();
emitter.emit('log');
Removes all listeners, or those of the specified eventName.
It is bad practice to remove listeners added elsewhere in the code,
particularly when the EventEmitter instance was created by some other
component or module (e.g. sockets or file streams).
Returns a reference to the EventEmitter, so that calls can be chained.
OptionaleventName: Removes the specified listener from the listener array for the event named
eventName.
const callback = (stream) => {
console.log('someone connected!');
};
server.on('connection', callback);
// ...
server.removeListener('connection', callback);
removeListener() will remove, at most, one instance of a listener from the
listener array. If any single listener has been added multiple times to the
listener array for the specified eventName, then removeListener() must be
called multiple times to remove each instance.
Once an event is emitted, all listeners attached to it at the
time of emitting are called in order. This implies that any
removeListener() or removeAllListeners() calls after emitting and
before the last listener finishes execution will not remove them from
emit() in progress. Subsequent events behave as expected.
import { EventEmitter } from 'node:events';
class MyEmitter extends EventEmitter {}
const myEmitter = new MyEmitter();
const callbackA = () => {
console.log('A');
myEmitter.removeListener('event', callbackB);
};
const callbackB = () => {
console.log('B');
};
myEmitter.on('event', callbackA);
myEmitter.on('event', callbackB);
// callbackA removes listener callbackB but it will still be called.
// Internal listener array at time of emit [callbackA, callbackB]
myEmitter.emit('event');
// Prints:
// A
// B
// callbackB is now removed.
// Internal listener array [callbackA]
myEmitter.emit('event');
// Prints:
// A
Because listeners are managed using an internal array, calling this will
change the position indexes of any listener registered after the listener
being removed. This will not impact the order in which listeners are called,
but it means that any copies of the listener array as returned by
the emitter.listeners() method will need to be recreated.
When a single function has been added as a handler multiple times for a single
event (as in the example below), removeListener() will remove the most
recently added instance. In the example the once('ping')
listener is removed:
import { EventEmitter } from 'node:events';
const ee = new EventEmitter();
function pong() {
console.log('pong');
}
ee.on('ping', pong);
ee.once('ping', pong);
ee.removeListener('ping', pong);
ee.emit('ping');
ee.emit('ping');
Returns a reference to the EventEmitter, so that calls can be chained.
set all the end point into a state where they do accept connections note: this method is useful for testing purpose
set all the end point into a state where they do accept connections note: this method is useful for testing purpose
Set ServerConfiguration.InApplicationSetup in
the address space.
Indicates whether the server is in its initial application setup phase (e.g. awaiting GDS provisioning).
By default EventEmitters will print a warning if more than 10 listeners are
added for a particular event. This is a useful default that helps finding
memory leaks. The emitter.setMaxListeners() method allows the limit to be
modified for this specific EventEmitter instance. The value can be set to
Infinity (or 0) to indicate an unlimited number of listeners.
Returns a reference to the EventEmitter, so that calls can be chained.
Replace the internal provider.
Accepts any ICertificateKeyPairProvider — wraps it
with location defaults if it lacks certificateFile/privateKeyFile.
Set or clear a temporary role-policy override.
When set, the override's getUserRoles(username)
is called before the default userManager.
Returning a NodeId[] overrides the roles;
returning null falls through to the default.
Call with null to remove the override and
restore default behavior.
Set the current server state.
Updates both the internal state and the
Server.ServerStatus.State variable in the
address space so that OPC UA reads reflect the
new state immediately.
shutdown all server endpoints
Optionaltimeout: number
the timeout (in ms) before the server is actually shutdown
// shutdown immediately
server.shutdown(function(err) {
});
// in typescript with promises
server.shutdown(10000).then(()=>{
console.log("Server has shutdown");
});
// shutdown within 10 seconds
server.engine.shutdownReason = coerceLocalizedText("Shutdown for maintenance");
server.shutdown(10000,function(err) {
});
shutdown all server endpoints
// shutdown immediately
server.shutdown(function(err) {
});
// in typescript with promises
server.shutdown(10000).then(()=>{
console.log("Server has shutdown");
});
// shutdown within 10 seconds
server.engine.shutdownReason = coerceLocalizedText("Shutdown for maintenance");
server.shutdown(10000,function(err) {
});
shutdown all server endpoints
the timeout (in ms) before the server is actually shutdown
// shutdown immediately
server.shutdown(function(err) {
});
// in typescript with promises
server.shutdown(10000).then(()=>{
console.log("Server has shutdown");
});
// shutdown within 10 seconds
server.engine.shutdownReason = coerceLocalizedText("Shutdown for maintenance");
server.shutdown(10000,function(err) {
});
Initiate the server by starting all its endpoints
Initiate the server by starting all its endpoints
set all the end point into a state where they do not accept further connections
note: this method is useful for testing purpose
set all the end point into a state where they do not accept further connections
note: this method is useful for testing purpose
Returns a string representation of an object.
Protectedverify
The OPC UA server.
OPCUAServercreates an OPC UA server that exposes an address space to connected clients. It handles secure channel management, session lifecycle, subscriptions, and the full OPC UA service set.Example