aio-libs / aio-libs/aiohttp

Support for HTTPS proxy with HTTPS destination using forwarding (w/o tunneling)

Abierto
#6,586 0 comentarios 1 reacción 0 asignados Ver en GitHub
enhancement
Lenguaje dominante
Python
Estrellas
16.5k
Forks
2.4k
Merge medio
17 h 22 min
PR fusionados (30 d)
212

Descripción

### Is your feature request related to a problem?

I am attempting to use aiohttp to connect to a TLS enabled endpoint using a TLS enabled proxy. Currently this only appears to be possible using the HTTP CONNECT tunneling method (aside from having to implement the workaround from aio-libs/aiohttp/discussions/6044 , which is out-of-scope of this request).

While this is understood to be the commonly "preferred" method, as it allows for end-to-end encryption, there are use cases where the proxy is considered trusted, and forwarding / re-encryption is not only acceptable, but desired (such as when utilizing security gateways for auditing, or development proxies to aid in packet inspection, etc).

### Describe the solution you'd like

Currently this supported synchronously using the urllib3.poolmanager.ProxyManager class, which [utilizes forwarding](https://urllib3.readthedocs.io/en/latest/advanced-usage.html#:~:text=for%20https%20proxies%20we%20also%20support%20forwarding%20your%20requests%20to%20https%20destinations%20with%20an%20absolute%20uri%20if%20the%20use_forwarding_for_https%20argument%20is%20set%20to%20true.%20we%20strongly%20recommend%20you%20only%20use%20this%20option%20with%20trusted%20or%20corporate%20proxies%20as%20the%20proxy%20will%20have%20full%20visibility%20of%20your%20requests.) via URIs in [absolute-form](https://datatracker.ietf.org/doc/html/rfc7230#section-5.3.2) without attempting to establish a tunnel.

If possible, I would like to see a similar "use_forwarding_for_https" flag added to the [_create_proxy_connection](https://github.com/aio-libs/aiohttp/blob/1dbfbb433f3f7cd05ca97288805dec9e296d75de/aiohttp/connector.py#L1146) method to allow for similar functionality.

### Describe alternatives you've considered

It has been considered to branch and use the ProxyManager instead of providing "proxy*" arguments into the aiohttp library calls; however, this will add a significant number of blocking calls into the call stack, and take way from the overall benefits of using asynchronous calls in the first place.

### Related component

Client

### Additional context

_No response_

### Code of Conduct

- [X] I agree to follow the aio-libs Code of Conduct

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.