Conversation
hyper-util's Tunnel and SocksV5 call the inner connector with the proxy's URI, so our connector saw an http scheme and never did TLS. An https request through a CONNECT or SOCKS5 proxy went into the tunnel as plaintext, which a real HTTPS server rejects, and verify_certs and the other TLS settings did nothing. The connector now opens the tunnel itself with the CONNECT and SOCKS5 handshakes raw_connect already uses, then does TLS with the target over it. Connections are still pooled. SOCKS5 credentials in the proxy URL are now sent, which they weren't before. An https:// proxy URL is refused for an https target, since that needs TLS inside TLS. Fixes #89
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #89.
HTTPS through a CONNECT or SOCKS5 proxy never did TLS with the target. hyper-util's
TunnelandSocksV5call the inner connector with the proxy's URI, so our connector sawhttpand skipped TLS, and the request went into the tunnel as plaintext. In practice that means proxied HTTPS just failed (a real HTTPS server rejects plaintext, and the new tests gotclient error (Canceled)), unless the proxy passed plaintext along, in which case the request leaked.OpenSslConnectornow opens the tunnel itself, using the CONNECT and SOCKS5 handshakesraw_connectalready uses, and then does TLS with the target over it. Connections are still pooled, and the TCP connection to the proxy is made the same way as before. hyper-util's proxy connectors are gone, along with itsclient-proxyfeature.Behavior changes:
verify_certs, cipher and TLS-version settings, andalpn_protocolsnow apply to proxied HTTPS.socks5://user:pass@host) are sent. They were silently ignored before.https://proxy URL is refused for HTTPS targets with a clear error, since that would need TLS inside TLS. It never worked. Plain-HTTP targets through anhttps://proxy URL are unchanged.tests/proxy_tls.rsruns a small CONNECT proxy and a small SOCKS5 proxy in front of the TLS test server, and checks that the first byte through the tunnel is a TLS handshake, that certificate verification applies to the target, and that SOCKS5 credentials arrive.