Repository navigation
fix(iroh-relay): send correct Proxy-Authorization credentials - #4591
Merged
Merged
Conversation
flub
approved these changes
Oct 8, 2026
flub
left a comment
Collaborator
There was a problem hiding this comment.
thanks! looks good i think
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Fixes #4561.
Now using
data_encoding::BASE64instead ofBASE64URLfor theProxy-Authorization: Basicheader indial_url_proxy.While writing the test for this, it turned out that there was a second problem in the header, related to the fact that
Url::username()andUrl::password()return the percent-encoded version. So if you had a password likes3cret>>(from the issue), it would be sendings3cret%3E%3Eto the proxy, and the alphabet wasn't even the problem. Ditto any other character that has to be escaped in URLs, like@or:. The second commit in this PR percent-decodes the username and password before encoding them. This matches the behavior of what reqwest does when given the same proxy URL, at least as far as non-invalid-UTF-8 characters go. And since #4463 the net_report probes will be sending that URL to reqwest, so there can currently be a mismatch between what the probes are sending and what we'd send when connecting to the relay.This makes
percent-encodinga direct dependency of iroh-relay. It's already an indirect one throughurl.Both of the tests added in this PR (which dial to a fake proxy and check the header it got) fail on main.
API Changes
n/a
Notes & open questions
Note that the percent-decoding goes a little beyond what we talked about in the issue. If you want, we can split that out into a different PR. It does change the behavior for literal
%signs followed by two hex characters in the password, which will now get decoded. Those would have to be written as%25, which matches the behavior of curl and reqwest.Change checklist