From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!.POSTED!not-for-mail From: David Engster Newsgroups: gmane.emacs.bugs Subject: bug#25518: 25.1.91; url-retrieve does not work with https over proxy Date: Tue, 24 Jan 2017 21:33:04 +0100 Message-ID: <871svs2o73.fsf@engster.org> References: NNTP-Posting-Host: blaine.gmane.org Mime-Version: 1.0 Content-Type: text/plain X-Trace: blaine.gmane.org 1485290220 29388 195.159.176.226 (24 Jan 2017 20:37:00 GMT) X-Complaints-To: usenet@blaine.gmane.org NNTP-Posting-Date: Tue, 24 Jan 2017 20:37:00 +0000 (UTC) User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/25.1 (gnu/linux) Cc: 25518@debbugs.gnu.org To: Andreas Schwab Original-X-From: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Tue Jan 24 21:36:53 2017 Return-path: Envelope-to: geb-bug-gnu-emacs@m.gmane.org Original-Received: from lists.gnu.org ([208.118.235.17]) by blaine.gmane.org with esmtp (Exim 4.84_2) (envelope-from ) id 1cW7pQ-0005iT-DY for geb-bug-gnu-emacs@m.gmane.org; Tue, 24 Jan 2017 21:36:32 +0100 Original-Received: from localhost ([::1]:55633 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1cW7pV-00088j-GK for geb-bug-gnu-emacs@m.gmane.org; Tue, 24 Jan 2017 15:36:37 -0500 Original-Received: from eggs.gnu.org ([2001:4830:134:3::10]:40274) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1cW7n5-0006XU-Ku for bug-gnu-emacs@gnu.org; Tue, 24 Jan 2017 15:34:09 -0500 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1cW7n0-00051D-Lw for bug-gnu-emacs@gnu.org; Tue, 24 Jan 2017 15:34:07 -0500 Original-Received: from debbugs.gnu.org ([208.118.235.43]:42601) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1cW7n0-000513-9M for bug-gnu-emacs@gnu.org; Tue, 24 Jan 2017 15:34:02 -0500 Original-Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1cW7n0-0003Ec-3j for bug-gnu-emacs@gnu.org; Tue, 24 Jan 2017 15:34:02 -0500 X-Loop: help-debbugs@gnu.org Resent-From: David Engster Original-Sender: "Debbugs-submit" Resent-CC: bug-gnu-emacs@gnu.org Resent-Date: Tue, 24 Jan 2017 20:34:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 25518 X-GNU-PR-Package: emacs X-GNU-PR-Keywords: Original-Received: via spool by 25518-submit@debbugs.gnu.org id=B25518.148528999212378 (code B ref 25518); Tue, 24 Jan 2017 20:34:02 +0000 Original-Received: (at 25518) by debbugs.gnu.org; 24 Jan 2017 20:33:12 +0000 Original-Received: from localhost ([127.0.0.1]:40800 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1cW7mC-0003DZ-10 for submit@debbugs.gnu.org; Tue, 24 Jan 2017 15:33:12 -0500 Original-Received: from randomsample.de ([5.45.97.173]:34953) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1cW7mA-0003DR-3M for 25518@debbugs.gnu.org; Tue, 24 Jan 2017 15:33:10 -0500 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=randomsample.de; s=a; h=Content-Type:MIME-Version:Message-ID:Date:References:In-Reply-To:Subject:Cc:To:From; bh=REd+qjI+jxInLGEslTqU+7GJiJrb+6GbOyWx6uLRIWY=; b=TkAB5K2D9ysKtbeVz3YnKVXsFtCkdKzi/9s1Pg6uXAK903qXVwKTwLZNTIclJCGt2Rs/OnMPYWjKXXXwKhf5UBj6frEffhtDV5N1AeAaLw2AMLdakMcsPxO+03Ot6avV; Original-Received: from ip4d16b353.dynamic.kabel-deutschland.de ([77.22.179.83] helo=isaac) by randomsample.de with esmtpsa (TLS1.2:RSA_AES_128_CBC_SHA1:128) (Exim 4.80) (envelope-from ) id 1cW7m8-00071o-D3; Tue, 24 Jan 2017 21:33:08 +0100 In-Reply-To: (Andreas Schwab's message of "Tue, 24 Jan 2017 14:25:01 +0100") Mail-Copies-To: never X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic] X-Received-From: 208.118.235.43 X-BeenThere: bug-gnu-emacs@gnu.org List-Id: "Bug reports for GNU Emacs, the Swiss army knife of text editors" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Original-Sender: "bug-gnu-emacs" Xref: news.gmane.org gmane.emacs.bugs:128385 Archived-At: Andreas Schwab writes: > url-retrieve should use CONNECT when talking to a https URL over a proxy > and then talk over the connection as if not using a proxy. > > ;; use locally running privoxy as proxy > (setq url-proxy-services '(("https" . "localhost:8118"))) > (with-current-buffer (url-retrieve-synchronously "https://www.heise.de") > (buffer-string)) => "HTTP/1.1 200 Connection established\n\n" Is this identical to #11788? If so, this is fixed only on master because it was deemed too risky for emacs-25. I'm still of the opinion that this is a serious security issue, because of the possible silent fallback to http without the user noticing. I'm always running my Emacs with 3c623c26a manually backported. -David