hysteria/app/internal/http
白日梦主义 8e78342c2b
fix(http): decode proxy Basic auth with standard base64 (#1596)
The HTTP proxy server's dispatch method decodes the Proxy-Authorization
Basic credential using base64.URLEncoding, but RFC 7617 specifies that
Basic authentication uses standard Base64 encoding (base64.StdEncoding).
The two encodings differ in their use of +/ vs -_ characters, so any
credential containing 0xff or other bytes that encode to / or + in
standard Base64 will fail to decode with URLEncoding, causing valid
authentication attempts to always be rejected with 407.

Additionally, the "Basic " scheme prefix check was case-sensitive, but
RFC 7235 section 2.1 specifies that auth-scheme is case-insensitive.

Fix both issues by switching to base64.StdEncoding and using
strings.ToLower for the scheme comparison.
2026-06-04 15:14:58 -07:00
..
server.go fix(http): decode proxy Basic auth with standard base64 (#1596) 2026-06-04 15:14:58 -07:00
server_test.go fix(http): decode proxy Basic auth with standard base64 (#1596) 2026-06-04 15:14:58 -07:00
server_test.py feat(wip): test reworks for app 2023-07-27 13:13:07 -07:00
test.crt feat: client http proxy 2023-06-10 19:08:00 -07:00
test.key feat: client http proxy 2023-06-10 19:08:00 -07:00