I read this and did not understand:
When you use the rogue certificate and rejectUnauthorized == false, you should see a TLS error being printed on the console, remeber to set rejectUnauthorized == true, to protect the web server.
Are you talking about if(!cleartextStream.authorized) part?