fix: auto-follow redirects in DynamicProxy to avoid HTTP downgrade warnings
Build and Push to GHCR / build-and-push (push) Has been cancelled
Build and Push to GHCR / build-and-push (push) Has been cancelled
GitHub download links (codeload.github.com) return 302 redirects to objects.githubusercontent.com. When ReverseProxy passes the 302 through to the browser, Chrome sees a HTTPS→HTTP redirect chain and shows "redirected through an insecure connection" + ERR_CACHE_WRITE_FAILURE. Add followRedirectTransport that uses http.Client to automatically follow 3xx redirects before ReverseProxy sees the response. The browser now receives the final ZIP content directly with a 200 status. via [HAPI](https://hapi.run) Co-Authored-By: HAPI <[email protected]>
This commit is contained in:
@@ -13,6 +13,20 @@ import (
|
||||
"mirror-proxy/internal/auth"
|
||||
)
|
||||
|
||||
// followRedirectTransport 包装 http.RoundTripper,自动跟随 3xx 重定向。
|
||||
// 用于 DynamicProxy,避免浏览器在 HTTP 代理上看到 HTTPS→HTTP 的 302 降级警告。
|
||||
type followRedirectTransport struct {
|
||||
base http.RoundTripper
|
||||
}
|
||||
|
||||
func (t *followRedirectTransport) RoundTrip(req *http.Request) (*http.Response, error) {
|
||||
client := &http.Client{
|
||||
Transport: t.base,
|
||||
CheckRedirect: func(req *http.Request, via []*http.Request) error { return nil },
|
||||
}
|
||||
return client.Do(req)
|
||||
}
|
||||
|
||||
// DynamicProxy 创建指向任意目标 URL 的反向代理
|
||||
func DynamicProxy(targetURL string) http.Handler {
|
||||
target, err := url.Parse(targetURL)
|
||||
@@ -92,11 +106,13 @@ func DynamicProxy(targetURL string) http.Handler {
|
||||
w.WriteHeader(http.StatusBadGateway)
|
||||
fmt.Fprintf(w, "Proxy error: %s", err.Error())
|
||||
},
|
||||
Transport: &http.Transport{
|
||||
MaxIdleConns: 100,
|
||||
MaxIdleConnsPerHost: 20,
|
||||
IdleConnTimeout: 90 * time.Second,
|
||||
TLSHandshakeTimeout: 10 * time.Second,
|
||||
Transport: &followRedirectTransport{
|
||||
base: &http.Transport{
|
||||
MaxIdleConns: 100,
|
||||
MaxIdleConnsPerHost: 20,
|
||||
IdleConnTimeout: 90 * time.Second,
|
||||
TLSHandshakeTimeout: 10 * time.Second,
|
||||
},
|
||||
},
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user