Re: rewriting the Host header, switching protocols
Fabian Keil <[email protected]> Sat, 17 Jun 2023 12:09:05 +0200
| Newsgroups | gmane.comp.web.privoxy.user |
|---|---|
| Message-ID | <[email protected]> |
--===============5618301153337578767== Content-Type: multipart/signed; boundary="Sig_/WrT30R5kNJRwN3d8OiZnncU"; protocol="application/pgp-signature"; micalg=pgp-sha256 --Sig_/WrT30R5kNJRwN3d8OiZnncU Content-Type: multipart/mixed; boundary="MP_/yNGQbkTxsykFEtkk+8NDg9Q" --MP_/yNGQbkTxsykFEtkk+8NDg9Q Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: quoted-printable Content-Disposition: inline Madhu <[email protected]> wrote on 2023-06-15 at 18:17:55: > * Fabian Keil <[email protected]> > Wrote on Thu, 23 Mar 2023 08:54:48 +0100 > > Madhu <[email protected]> wrote on 2023-03-23 at 09:55:27: >=20 > >> 1. To rewrite the Host: header of a forwarded request to a target > >> webserver (based on certain criteria) > > This is supported and can be done with a client-header filter: > > https://www.privoxy.org/user-manual/actions-file.html#CLIENT-HEADER-FIL= TER > > > > You can use tags or URL patterns to decide when to apply the filter. >=20 > Thanks. I was able to get this working easily with the excellent > documentation. Great. > >> 2. To switch the protocol from HTTPS to HTTP when forwarding a request > >> to another proxy (typically local, again based on certain criteria) > > > > This can be done by rewriting the protocol in the URL > > in the request line with a client-header filter. >=20 > Since the host isn't available in the client-header-filter I figure > this means that there has to be as many client filters as there are > hosts involved. This is not really a problem. Actually a dynamic filter can use the $host variable: https://www.privoxy.org/gitweb/?p=3Dprivoxy.git;a=3Dblob;f=3Ddefault.filter= ;h=3Daaf70a3e242c9944248dcac8316cc4599be0b8b8;hb=3DHEAD#l57 > I think I have a problem if I want to chain a forwarding action after > the downgrade to http - with a user actions file section like this: >=20 > ``` > { +client-header-filter{downgrade-http-on-wwwhost} \ > +forward-override{ forward <http-proxyhost>:<http-proxyport> } } > wwwhost/ > ``` > called by a `curl -v -x localhost:8118 https://<wwwwhost>' request >=20 > privoxy initially scans a "CONNECT <wwwhost>:443 HTTP/1.1" line from > curl, correctly applies the client header filters, detects the > rewritten header and the http downgrade, and rewrites the request > lines, but the new HTTP request line to send to the forwarding proxy > is "CONNECT <wwwhost>:80 HTTP/1.1" to establish a proxy tunnel but > since the protocol is now http I'd like it to be "GET http://<wwwhost> > HTTP/1.1" >=20 > Does this need a new sort of forwarding action? Thanks for the report. As it turns out this is a bug. The attached lightly-tested patch should get this working. Fabian --MP_/yNGQbkTxsykFEtkk+8NDg9Q Content-Type: text/x-patch Content-Transfer-Encoding: quoted-printable Content-Disposition: attachment; filename=0001-build_request_line-Use-server_use_ssl-instead-of-cli.patch =46rom 287f25d618f033b026c0fc66216ab545f7b9338f Mon Sep 17 00:00:00 2001 From: Fabian Keil <[email protected]> Date: Sat, 17 Jun 2023 11:57:52 +0200 Subject: [PATCH] build_request_line(): Use server_use_ssl() instead of client_use_ssl() ... to decide whether or not to emit a CONNECT request when talking to a forwarding proxy. Gets downgrades from https to http working when using a forwarding proxy. Reported by: Madhu --- jcc.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/jcc.c b/jcc.c index bd0155e3..f140033b 100644 --- a/jcc.c +++ b/jcc.c @@ -1016,7 +1016,7 @@ static void build_request_line(struct client_state *c= sp, const struct forward_sp freez(*request_line); #ifdef FEATURE_HTTPS_INSPECTION if (fwd !=3D NULL && fwd->forward_host && - fwd->type !=3D FORWARD_WEBSERVER && client_use_ssl(csp)) + fwd->type !=3D FORWARD_WEBSERVER && server_use_ssl(csp)) { *request_line =3D strdup("CONNECT "); } @@ -1030,7 +1030,7 @@ static void build_request_line(struct client_state *c= sp, const struct forward_sp if (fwd !=3D NULL && fwd->forward_host && fwd->type !=3D FORWARD_WEBSER= VER) { #ifdef FEATURE_HTTPS_INSPECTION - if (client_use_ssl(csp)) + if (server_use_ssl(csp)) { char port_string[10]; =20 --=20 2.40.1 --MP_/yNGQbkTxsykFEtkk+8NDg9Q-- --Sig_/WrT30R5kNJRwN3d8OiZnncU Content-Type: application/pgp-signature Content-Description: OpenPGP digital signature -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEETzbBfzgWkTZUoehQaRgikYuiNxwFAmSNhkIACgkQaRgikYui NxwgWg//Q2WnrCt3vJRj8YBwMOSvKagw7zOay8IZvncIVfeLXcZHk2psW0au2CNr wATnjxgrVeecKfIT+HnMy0Us4mFT3YMTpvquc79eJhRiIdax0XOZlSaa2iNCHhU1 0NC/jhQG54lynSnahp1adjCTwJ10iSlA00uFndsotUGqVNVHrQmgHdDdpSbjipSS DzxB5wELbQTGSI+V8aF2MgpeNBCWTI9tc8S2f1MVSVTcUObLXKHCJ0bksLSMzh1q 9DrxqcgBkUfTwzdVdXmHkwp8EAA1+40iSwJZQkMc5v0wLd8vxejyvncCgT4nvA0I IzZYpKMDFu0QEiIGa29LccAcGF/hJzEC3DUGTvwgIh9pVC3hMisU4h8VyR4bwgq2 DzpEaRFjA5Eg1CM70qexASqubt+0PRDxGhEj2ayWQF+mUUamhkIgkFaicT+o83SB qvJv9Tc7YWpyLXZHxuowF+jHkb31xmPVLB9Mi9wJ8B7W7NqDgik8+EoVziWNVDLT 8Y5SSvEkE1qTYuvREuszmuNNVNIB4I5Q13Bk0cDutlTGo18clR3rtp7LrPCCo6LM F85VQz+0imjiA8MBj2YIEKioi7hiJ0wUWE1wq9BPSjnamdgfKlPrhSTNTIKLIKMA pa9EI66yOsTDIbX77LGO1xhXcpDpDuZD0QjcJTPdHuSSAozBTYg= =iErS -----END PGP SIGNATURE----- --Sig_/WrT30R5kNJRwN3d8OiZnncU-- --===============5618301153337578767== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Privoxy-users mailing list [email protected] https://lists.privoxy.org/mailman/listinfo/privoxy-users --===============5618301153337578767==--