Some checks failed
build-packages / resolve bundled mosh-client (push) Has been cancelled
build-packages / resolve bundled et-client (push) Has been cancelled
build-packages / build-macos (push) Has been cancelled
build-packages / build-windows (push) Has been cancelled
build-packages / build-linux-x64 (push) Has been cancelled
build-packages / build-linux-arm64 (push) Has been cancelled
build-packages / release (push) Has been cancelled
build-packages / update Nix release metadata (push) Has been cancelled
build-packages / bump homebrew tap (push) Has been cancelled
test / lint-and-test (push) Has been cancelled
AI automation / Route event (push) Has been cancelled
AI automation / Hand reopened issue to maintainers (push) Has been cancelled
AI automation / Clean source issue state (push) Has been cancelled
AI automation / Reconcile handoffs (push) Has been cancelled
AI automation / Classify issue (push) Has been cancelled
AI automation / Claude Code smoke (push) Has been cancelled
AI automation / Review issue follow-up (push) Has been cancelled
AI automation / Publish issue follow-up (push) Has been cancelled
AI automation / Implement with Claude Code (push) Has been cancelled
AI automation / Publish implement PR (push) Has been cancelled
AI automation / Continue queued issue comments (push) Has been cancelled
AI automation / Codex review loop (push) Has been cancelled
AI automation / Publish Codex fix (push) Has been cancelled
AI automation / Clear Codex dispatch marker (push) Has been cancelled
AI automation / Own PR re-request Codex (push) Has been cancelled
AI automation / External PR re-request Codex (push) Has been cancelled
AI automation / Poll Codex reaction / retry (push) Has been cancelled
build-et-binaries / build-linux-x64 (push) Has been cancelled
build-et-binaries / build-linux-arm64 (push) Has been cancelled
build-et-binaries / build-macos-universal (push) Has been cancelled
build-et-binaries / build-windows-x64 (push) Has been cancelled
build-et-binaries / release (push) Has been cancelled
64 lines
2.4 KiB
JavaScript
64 lines
2.4 KiB
JavaScript
const test = require("node:test");
|
|
const assert = require("node:assert/strict");
|
|
|
|
const {
|
|
proxyInfoFromResolveResult,
|
|
createAgentFromProxyUrl,
|
|
applyInsecureTargetTls,
|
|
} = require("./httpNetworkProxyAgent.cjs");
|
|
|
|
test("proxyInfoFromResolveResult parses Chromium PROXY / SOCKS / DIRECT", () => {
|
|
assert.equal(proxyInfoFromResolveResult("DIRECT"), null);
|
|
assert.equal(proxyInfoFromResolveResult("PROXY 127.0.0.1:7890"), "http://127.0.0.1:7890");
|
|
assert.equal(proxyInfoFromResolveResult("HTTPS proxy.example:8443"), "https://proxy.example:8443");
|
|
assert.equal(proxyInfoFromResolveResult("SOCKS5 127.0.0.1:1080"), "socks5://127.0.0.1:1080");
|
|
assert.equal(
|
|
proxyInfoFromResolveResult("PROXY 10.0.0.1:8080; DIRECT"),
|
|
"http://10.0.0.1:8080",
|
|
);
|
|
});
|
|
|
|
test("createAgentFromProxyUrl builds http(s) and socks agents", () => {
|
|
const httpsAgent = createAgentFromProxyUrl("http://127.0.0.1:7890", true);
|
|
assert.ok(httpsAgent);
|
|
assert.match(httpsAgent.constructor.name, /ProxyAgent/);
|
|
|
|
const httpAgent = createAgentFromProxyUrl("http://127.0.0.1:7890", false);
|
|
assert.ok(httpAgent);
|
|
|
|
const socksAgent = createAgentFromProxyUrl("socks5://127.0.0.1:1080", true);
|
|
assert.ok(socksAgent);
|
|
});
|
|
|
|
test("createAgentFromProxyUrl can disable TLS verification for insecure endpoints", () => {
|
|
const agent = createAgentFromProxyUrl("http://127.0.0.1:7890", true, {
|
|
rejectUnauthorized: false,
|
|
});
|
|
assert.ok(agent);
|
|
// allowInsecure must NOT weaken TLS to the proxy hop itself.
|
|
assert.notEqual(agent.connectOpts?.rejectUnauthorized, false);
|
|
// Wrapper must be installed so target TLS upgrades get rejectUnauthorized:false.
|
|
assert.equal(typeof agent.connect, "function");
|
|
assert.notEqual(agent.connect, Object.getPrototypeOf(agent).connect);
|
|
|
|
const httpsProxyAgent = createAgentFromProxyUrl("https://proxy.example:8443", true, {
|
|
rejectUnauthorized: false,
|
|
});
|
|
assert.ok(httpsProxyAgent);
|
|
assert.notEqual(httpsProxyAgent.connectOpts?.rejectUnauthorized, false);
|
|
assert.notEqual(httpsProxyAgent.connect, Object.getPrototypeOf(httpsProxyAgent).connect);
|
|
});
|
|
|
|
test("applyInsecureTargetTls forces rejectUnauthorized on tunneled target connect", () => {
|
|
let seenOpts;
|
|
const fakeAgent = {
|
|
connect(_req, opts) {
|
|
seenOpts = opts;
|
|
return opts;
|
|
},
|
|
};
|
|
applyInsecureTargetTls(fakeAgent);
|
|
fakeAgent.connect({}, { host: "example.com", port: 443, rejectUnauthorized: true });
|
|
assert.equal(seenOpts.rejectUnauthorized, false);
|
|
});
|