Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

6 changes: 4 additions & 2 deletions gix-transport/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,8 @@ http-client-curl-openssl = ["http-client-curl", "curl/ssl"]
## Implies `http-client` and adds support for http transports using the blocking version of `reqwest`.
## NOTE: `https://` is NOT supported by default. You must enable one of the `http-client-reqwest-rust-tls`
## or `http-client-reqwest-native-tls` features to enable HTTPS support.
http-client-reqwest = ["reqwest", "http-client"]
## With the current reqwest version, SOCKS proxies also require one of the TLS features.
http-client-reqwest = ["reqwest", "http-client", "dep:hyper-util"]
## Stacks with `http-client-reqwest` and enables `https://` via the `rustls` crate.
http-client-reqwest-rust-tls = ["http-client-reqwest", "reqwest/rustls"]
## Stacks with `http-client-reqwest` and enables `https://` via the `rustls` crate.
Expand Down Expand Up @@ -125,7 +126,8 @@ curl = { version = "0.4", optional = true, default-features = false }

# for http-client-reqwest
# all but the 'default-tls' feature
reqwest = { version = "0.13.4", optional = true, default-features = false, features = ["blocking", "charset", "http2"] }
reqwest = { version = "0.13.4", optional = true, default-features = false, features = ["blocking", "charset", "http2", "socks"] }
hyper-util = { version = "0.1.20", optional = true, default-features = false, features = ["client-proxy"] }

## If used in conjunction with `async-client`, the `connect()` method will become available along with supporting the git protocol over TCP,
## where the TCP stream is created using this crate.
Expand Down
13 changes: 12 additions & 1 deletion gix-transport/src/client/blocking_io/http/curl/remote.rs
Original file line number Diff line number Diff line change
Expand Up @@ -493,7 +493,18 @@ pub fn new() -> Worker {
}

let mut proxy_auth_action = None;
if let Some(proxy) = proxy {
if let Some(mut proxy) = proxy {
if proxy_authenticate.is_some() && !proxy.is_empty() {
if !proxy.contains("://") {
proxy.insert_str(0, "http://");
}
let mut proxy_url =
gix_url::parse(proxy.as_str()).or_raise(|| message("Could not parse proxy URL"))?;
// Libcurl gives URL credentials precedence over the helper's username/password options.
proxy_url.user = None;
proxy_url.password = None;
proxy = proxy_url.to_bstring().to_string();
}
curl!(handle.proxy(&proxy));
let proxy_type = if proxy.starts_with("socks5h") {
curl::easy::ProxyType::Socks5Hostname
Expand Down
10 changes: 8 additions & 2 deletions gix-transport/src/client/blocking_io/http/mod.rs
Original file line number Diff line number Diff line change
Expand Up @@ -32,8 +32,11 @@ pub mod curl;

/// The experimental `reqwest` backend.
///
/// It doesn't support any of the shared http options yet, but can be seen as example on how to integrate blocking `http` backends.
/// There is also nothing that would prevent it from becoming a fully-featured HTTP backend except for demand and time.
/// Supports extra headers, redirects, HTTP/HTTPS and SOCKS proxies, proxy bypass lists, and proxy credential helpers.
/// HTTP proxy authentication uses preemptive Basic authentication for both `Basic` and `AnyAuth`; other methods and
/// Unix socket proxy paths and SOCKS4 user IDs are rejected. With the current reqwest version, SOCKS proxies also require
/// a TLS feature.
/// Other shared HTTP options are not supported yet.
#[cfg(feature = "http-client-reqwest")]
pub mod reqwest;

Expand Down Expand Up @@ -145,6 +148,7 @@ pub struct Options {
/// A curl-style proxy declaration of the form `[protocol://][user[:password]@]proxyhost[:port]`.
///
/// Note that an empty string means the proxy is disabled entirely.
/// If unset, the backend selects proxy environment variables for each requested URL.
/// Refers to `http.proxy`.
pub proxy: Option<String>,
/// The comma-separated list of hosts to not send through the `proxy`, or `*` to entirely disable all proxying.
Expand All @@ -155,6 +159,8 @@ pub struct Options {
pub proxy_auth_method: options::ProxyAuthMethod,
/// If authentication is needed for the proxy as its URL contains a username, this method must be set to provide a password
/// for it before making the request, and to store it if the connection succeeds.
/// When `proxy` is unset, reqwest creates each `Get` action from the selected environment proxy URL, which can change
/// on redirects. The callback must select credentials for that URL.
pub proxy_authenticate: Option<(gix_credentials::helper::Action, Arc<Mutex<options::AuthenticateFn>>)>,
/// The `HTTP` `USER_AGENT` string presented to an `HTTP` server, notably not the user agent present to the `git` server.
///
Expand Down
Loading
Loading