mirror of
https://github.com/yhirose/cpp-httplib.git
synced 2026-09-30 20:52:31 +07:00
* send each credential only to its own hop in write_request An SSLClient behind a proxy sent Proxy-Authorization inside the TLS tunnel, where the origin reads it, and sent the origin's Authorization on the CONNECT request the proxy reads. Attach each only on the message its hop actually reads. * Keep default headers off the CONNECT request set_default_headers() is typically used for origin credentials such as Authorization, Cookie or API keys, but they were also attached to the CONNECT request an SSLClient sends to its proxy, in plaintext before the TLS tunnel exists. Default headers now go only on requests the origin reads, the same split the previous commit makes for set_basic_auth and set_bearer_token_auth. Claude-Session: https://claude.ai/code/session_01JYPWKpbp4a881EdpEf2xSi * Simplify per-hop credential handling and its tests Flatten the Authorization insertion in write_request into one guard with an else-if (Basic already took precedence over Bearer), and shorten the comments around it. Fold DefaultHeadersStayOffConnect into the CredentialsStayWithTheirHop helper, which now takes the list of headers that must reach only the origin. Claude-Session: https://claude.ai/code/session_01JYPWKpbp4a881EdpEf2xSi --------- Co-authored-by: yhirose <yuji.hirose.bug@gmail.com>