Skip to content

Add HTTPS and MITM support - #40

Closed
prashanthpai wants to merge 1 commit into
superfly:mainfrom
prashanthpai:ppai/mitm-tls
Closed

prashanthpai wants to merge 1 commit into
superfly:mainfrom
prashanthpai:ppai/mitm-tls

Conversation

@prashanthpai

Copy link
Copy Markdown

This change is mostly a continuation of this PR: #34

Usecase:

We have instances of sources/tools (like SDKs) where:

  1. source supports/honours http_proxy and HTTPS_PROXY env vars like curl does
  2. we cannot replace https with http
  3. we cannot inject Proxy-Tokenizer

3 is addressed by #39

Signed-off-by: Prashanth Pai <411294+prashanthpai@users.noreply.github.com>
@mjbraun

mjbraun commented Sep 15, 2026

Copy link
Copy Markdown
Contributor

Closing this: since #56, tokenizer refuses CONNECT on purpose as the CONNECT/MITM path let the Host header and the dialed host diverge, which broke allowed_hosts pinning (fixed in v119). Supporting SDKs that only speak HTTPS_PROXY would mean reintroducing CONNECT with the host checks bound to the CONNECT target, which is a design change rather than a rebase. If the need is still live, open an issue describing the SDK and we'll take it up there.

@mjbraun mjbraun closed this Sep 15, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants