Skip to content

fix(iroh-relay): send correct Proxy-Authorization credentials - #4591

Merged
ramfox merged 2 commits into
n0-computer:mainfrom
kalapowered:relay-proxy-auth-base64
Oct 8, 2026
Merged

ramfox merged 2 commits into
n0-computer:mainfrom
kalapowered:relay-proxy-auth-base64

Conversation

@fluffypony

Copy link
Copy Markdown
Contributor

Description

Fixes #4561.

Now using data_encoding::BASE64 instead of BASE64URL for the Proxy-Authorization: Basic header in dial_url_proxy.

While writing the test for this, it turned out that there was a second problem in the header, related to the fact that Url::username() and Url::password() return the percent-encoded version. So if you had a password like s3cret>> (from the issue), it would be sending s3cret%3E%3E to the proxy, and the alphabet wasn't even the problem. Ditto any other character that has to be escaped in URLs, like @ or :. The second commit in this PR percent-decodes the username and password before encoding them. This matches the behavior of what reqwest does when given the same proxy URL, at least as far as non-invalid-UTF-8 characters go. And since #4463 the net_report probes will be sending that URL to reqwest, so there can currently be a mismatch between what the probes are sending and what we'd send when connecting to the relay.

This makes percent-encoding a direct dependency of iroh-relay. It's already an indirect one through url.

Both of the tests added in this PR (which dial to a fake proxy and check the header it got) fail on main.

API Changes

n/a

Notes & open questions

Note that the percent-decoding goes a little beyond what we talked about in the issue. If you want, we can split that out into a different PR. It does change the behavior for literal % signs followed by two hex characters in the password, which will now get decoded. Those would have to be written as %25, which matches the behavior of curl and reqwest.

Change checklist

  • Self-review.
  • Documentation updates following the style guide, if relevant.
  • Tests if relevant.
  • All API changes documented.

@n0bot n0bot Bot added this to iroh Oct 8, 2026

@flub flub left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thanks! looks good i think

@ramfox
ramfox added this pull request to the merge queue Oct 8, 2026
Merged via the queue into n0-computer:main with commit d4490fc Oct 8, 2026
38 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: ✅ Done

Development

Successfully merging this pull request may close these issues.

Relay client sends Proxy-Authorization in the URL-safe base64 alphabet

3 participants