Re: rewriting the Host header, switching protocols

Fabian Keil <[email protected]> Sat, 17 Jun 2023 12:09:05 +0200
Newsgroups gmane.comp.web.privoxy.user
Message-ID <[email protected]>
--===============5618301153337578767==
Content-Type: multipart/signed; boundary="Sig_/WrT30R5kNJRwN3d8OiZnncU";
 protocol="application/pgp-signature"; micalg=pgp-sha256

--Sig_/WrT30R5kNJRwN3d8OiZnncU
Content-Type: multipart/mixed; boundary="MP_/yNGQbkTxsykFEtkk+8NDg9Q"

--MP_/yNGQbkTxsykFEtkk+8NDg9Q
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline

Madhu <[email protected]> wrote on 2023-06-15 at 18:17:55:

> *  Fabian Keil <[email protected]>
> Wrote on Thu, 23 Mar 2023 08:54:48 +0100
> > Madhu <[email protected]> wrote on 2023-03-23 at 09:55:27:
>=20
> >> 1.  To rewrite the Host: header of a forwarded request to a target
> >> webserver (based on certain criteria)
> > This is supported and can be done with a client-header filter:
> > https://www.privoxy.org/user-manual/actions-file.html#CLIENT-HEADER-FIL=
TER
> >
> > You can use tags or URL patterns to decide when to apply the filter.
>=20
> Thanks. I was able to get this working easily with the excellent
> documentation.

Great.

> >> 2. To switch the protocol from HTTPS to HTTP when forwarding a request
> >> to another proxy (typically local, again based on certain criteria)
> >
> > This can be done by rewriting the protocol in the URL
> > in the request line with a client-header filter.
>=20
> Since the host isn't available in the client-header-filter I figure
> this means that there has to be as many client filters as there are
> hosts involved.  This is not really a problem.

Actually a dynamic filter can use the $host variable:
https://www.privoxy.org/gitweb/?p=3Dprivoxy.git;a=3Dblob;f=3Ddefault.filter=
;h=3Daaf70a3e242c9944248dcac8316cc4599be0b8b8;hb=3DHEAD#l57

> I think I have a problem if I want to chain a forwarding action after
> the downgrade to http - with a user actions file section like this:
>=20
> ```
> { +client-header-filter{downgrade-http-on-wwwhost} \
>  +forward-override{ forward  <http-proxyhost>:<http-proxyport> } }
> wwwhost/
> ```
> called by a `curl -v -x localhost:8118 https://<wwwwhost>' request
>=20
> privoxy initially scans a "CONNECT <wwwhost>:443 HTTP/1.1" line from
> curl, correctly applies the client header filters, detects the
> rewritten header and the http downgrade, and rewrites the request
> lines, but the new HTTP request line to send to the forwarding proxy
> is "CONNECT <wwwhost>:80 HTTP/1.1" to establish a proxy tunnel but
> since the protocol is now http I'd like it to be "GET http://<wwwhost>
> HTTP/1.1"
>=20
> Does this need a new sort of forwarding action?

Thanks for the report. As it turns out this is a bug.

The attached lightly-tested patch should get this working.

Fabian

--MP_/yNGQbkTxsykFEtkk+8NDg9Q
Content-Type: text/x-patch
Content-Transfer-Encoding: quoted-printable
Content-Disposition: attachment;
 filename=0001-build_request_line-Use-server_use_ssl-instead-of-cli.patch

=46rom 287f25d618f033b026c0fc66216ab545f7b9338f Mon Sep 17 00:00:00 2001
From: Fabian Keil <[email protected]>
Date: Sat, 17 Jun 2023 11:57:52 +0200
Subject: [PATCH] build_request_line(): Use server_use_ssl() instead of
 client_use_ssl()

... to decide whether or not to emit a CONNECT request
when talking to a forwarding proxy.

Gets downgrades from https to http working when using
a forwarding proxy.

Reported by: Madhu
---
 jcc.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/jcc.c b/jcc.c
index bd0155e3..f140033b 100644
--- a/jcc.c
+++ b/jcc.c
@@ -1016,7 +1016,7 @@ static void build_request_line(struct client_state *c=
sp, const struct forward_sp
    freez(*request_line);
 #ifdef FEATURE_HTTPS_INSPECTION
    if (fwd !=3D NULL && fwd->forward_host &&
-       fwd->type !=3D FORWARD_WEBSERVER && client_use_ssl(csp))
+       fwd->type !=3D FORWARD_WEBSERVER && server_use_ssl(csp))
    {
       *request_line =3D strdup("CONNECT ");
    }
@@ -1030,7 +1030,7 @@ static void build_request_line(struct client_state *c=
sp, const struct forward_sp
    if (fwd !=3D NULL && fwd->forward_host && fwd->type !=3D FORWARD_WEBSER=
VER)
    {
 #ifdef FEATURE_HTTPS_INSPECTION
-      if (client_use_ssl(csp))
+      if (server_use_ssl(csp))
       {
          char port_string[10];
=20
--=20
2.40.1


--MP_/yNGQbkTxsykFEtkk+8NDg9Q--

--Sig_/WrT30R5kNJRwN3d8OiZnncU
Content-Type: application/pgp-signature
Content-Description: OpenPGP digital signature

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEETzbBfzgWkTZUoehQaRgikYuiNxwFAmSNhkIACgkQaRgikYui
NxwgWg//Q2WnrCt3vJRj8YBwMOSvKagw7zOay8IZvncIVfeLXcZHk2psW0au2CNr
wATnjxgrVeecKfIT+HnMy0Us4mFT3YMTpvquc79eJhRiIdax0XOZlSaa2iNCHhU1
0NC/jhQG54lynSnahp1adjCTwJ10iSlA00uFndsotUGqVNVHrQmgHdDdpSbjipSS
DzxB5wELbQTGSI+V8aF2MgpeNBCWTI9tc8S2f1MVSVTcUObLXKHCJ0bksLSMzh1q
9DrxqcgBkUfTwzdVdXmHkwp8EAA1+40iSwJZQkMc5v0wLd8vxejyvncCgT4nvA0I
IzZYpKMDFu0QEiIGa29LccAcGF/hJzEC3DUGTvwgIh9pVC3hMisU4h8VyR4bwgq2
DzpEaRFjA5Eg1CM70qexASqubt+0PRDxGhEj2ayWQF+mUUamhkIgkFaicT+o83SB
qvJv9Tc7YWpyLXZHxuowF+jHkb31xmPVLB9Mi9wJ8B7W7NqDgik8+EoVziWNVDLT
8Y5SSvEkE1qTYuvREuszmuNNVNIB4I5Q13Bk0cDutlTGo18clR3rtp7LrPCCo6LM
F85VQz+0imjiA8MBj2YIEKioi7hiJ0wUWE1wq9BPSjnamdgfKlPrhSTNTIKLIKMA
pa9EI66yOsTDIbX77LGO1xhXcpDpDuZD0QjcJTPdHuSSAozBTYg=
=iErS
-----END PGP SIGNATURE-----

--Sig_/WrT30R5kNJRwN3d8OiZnncU--

--===============5618301153337578767==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Privoxy-users mailing list
[email protected]
https://lists.privoxy.org/mailman/listinfo/privoxy-users

--===============5618301153337578767==--