summaryrefslogtreecommitdiff
path: root/crates/arti/src/proxy
Commit message (Collapse)AuthorAgeFilesLines
* Merge branch 'ticket_2259' into 'main'Nick Mathewson2025-11-251-1/+26
|\ | | | | | | | | | | | | arti: Put supported request headers in Tor-Capabilties Closes #2259 See merge request tpo/core/arti!3473
| * arti: Put supported request headers in Tor-CapabiltiesNick Mathewson2025-11-181-1/+26
| | | | | | | | | | | | This is for spec conformance; it is a missing piece of prop365. Closes #2259.
* | http-connect: use end reason for http status if possibleNick Mathewson2025-11-241-1/+38
| | | | | | | | | | The spec includes a direct conversion from END reason fields to HTTP status codes, so we should follow it if we have an END reason.
* | http_connect: Report end reasons for HTTP CONNECT failures.Nick Mathewson2025-11-191-6/+27
| |
* | tor-error: Provide a more reasonable API for http status codes.Nick Mathewson2025-11-181-2/+2
| |
* | tor-error: Add support for ErrorKind->HTTP status conversionNick Mathewson2025-11-181-78/+2
|/ | | | | | | It makes more sense to have the conversion here, so it can use an exhaustive match over ErrorKind. This isn't the final API; I'm just moving the code from `arti`.
* http_connect: Add AsyncReadExt to fix compilation.Nick Mathewson2025-11-131-2/+2
|
* Merge branch 'http_xsprobe' into 'main'Nick Mathewson2025-11-131-1/+142
|\ | | | | | | | | Validate Host header for non-CONNECT requests to HTTP CONNECT port See merge request tpo/core/arti!3429
| * http_connect: prevent tests from colliding on directoriesNick Mathewson2025-11-131-5/+16
| |
| * http_connect: fix to conform to MSRVNick Mathewson2025-11-131-1/+1
| |
| * http_connect: add a test for Host validation.Nick Mathewson2025-11-131-0/+73
| |
| * Validate Host header for non-CONNECT requests to HTTP CONNECT portNick Mathewson2025-11-031-1/+58
| | | | | | | | | | | | | | This validation makes it harder for an adversarial webpage to probe for the version of arti and its capabilities. See torspec!437.
* | Add a notion of isolation strong enough to enable long-lived circuits.Nick Mathewson2025-11-121-0/+22
| | | | | | | | Part of prop368.
* | Fix name of clippy lint to unchecked_time_subtraction (2)Ian Jackson2025-11-061-1/+1
| | | | | | | | Run maint/add_warning
* | all: replace all uses of `futures::task::SpawnExt` with `tor_rtcompat::SpawnExt`Steven Engler2025-11-041-1/+1
| |
* | Replace copy_interactive with futures-copy.Nick Mathewson2025-10-302-45/+29
|/ | | | | | | | This change lets us avoid spawning extra tasks (due to one-direction nature of copy_interactive), and avoid some lock contention (due to use of AsyncReadExt::split). Addresses part of #786.
* arti: Remove now-needless cognitive_complexity exceptionsNick Mathewson2025-10-281-1/+0
| | | | | | | Apparently the http_connect refactoring made these no longer trigger. Closes #2226
* http_connect: Remove (most) X- prefixes.Nick Mathewson2025-10-281-21/+38
| | | | | | We can't remove them all, since X-Tor-Stream-Isolation is recognized by C-Tor. I've added a non-deprecated Tor-Stream-Isolation that works indepenently.
* http_connect: write our own hyper-futures replacementNick Mathewson2025-10-281-4/+77
|
* http_connect: Forbid non-empty OPTIONS bodies.Nick Mathewson2025-10-281-0/+8
|
* http_connect: validate casei behavior of HeaderMap.Nick Mathewson2025-10-281-0/+36
|
* http_connect: Declare that error messages are text/plain.Nick Mathewson2025-10-281-1/+1
|
* http_connect: Reject OPTIONS requests with bodiesNick Mathewson2025-10-281-2/+11
|
* http_connect: Implement stream isolationNick Mathewson2025-10-281-4/+74
|
* http_connect: implement rpc supportNick Mathewson2025-10-281-6/+76
|
* http-connect: Implement X-Tor-Family-PreferenceNick Mathewson2025-10-281-5/+79
|
* http_connect: Use consts for headers.Nick Mathewson2025-10-281-4/+16
|
* http_connect: Generate an X-Tor-Request-Failed header.Nick Mathewson2025-10-281-2/+20
|
* http_connect: Provide better status codes for ErrorKinds.Nick Mathewson2025-10-282-4/+77
|
* arti: Implement a "bilingual" HTTP CONNECT proxy.Nick Mathewson2025-10-281-0/+325
| | | | | | | | | | | With his commit, our SOCKS ports now accept both SOCKS and HTTP CONNECT requests, per proposal 365. There are still some infelicities, marked with "XXXX" or "TODO". I've tested this with curl, though, and it works. :) Typo-fixes-by: Gabriela Moldovan <[email protected]>
* arti: Detect proxy protocol _before_ starting SOCKS.Nick Mathewson2025-10-282-23/+14
| | | | | This will let us speak HTTP CONNECT as well; there is a stub for initiating an http proxy.
* arti: Pass a buffered stream to handle_socks_connNick Mathewson2025-10-281-2/+11
| | | | This will let us implement bilingual HTTP proxies.
* arti: Renaming around socks/generic proxiesNick Mathewson2025-10-281-10/+10
| | | | This is _all_ renaming and comment adjustments.
* arti: Split socks-specific parts out of handle_socks_connNick Mathewson2025-10-281-0/+463
We want to abstract every part of this code that knows that it's speaking SOCKS, so that we can in turn add a new proxy type. Note that several methods and types here have names that are no longer appropriate for their functionality. I'll revise those in a later commit.