[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
bug#25518: 25.1.91; url-retrieve does not work with https over proxy
From: |
David Engster |
Subject: |
bug#25518: 25.1.91; url-retrieve does not work with https over proxy |
Date: |
Tue, 24 Jan 2017 21:33:04 +0100 |
User-agent: |
Gnus/5.13 (Gnus v5.13) Emacs/25.1 (gnu/linux) |
Andreas Schwab writes:
> url-retrieve should use CONNECT when talking to a https URL over a proxy
> and then talk over the connection as if not using a proxy.
>
> ;; use locally running privoxy as proxy
> (setq url-proxy-services '(("https" . "localhost:8118")))
> (with-current-buffer (url-retrieve-synchronously "https://www.heise.de")
> (buffer-string)) => "HTTP/1.1 200 Connection established\n\n"
Is this identical to #11788? If so, this is fixed only on master because
it was deemed too risky for emacs-25. I'm still of the opinion that this
is a serious security issue, because of the possible silent fallback to
http without the user noticing. I'm always running my Emacs with
3c623c26a manually backported.
-David