Commit 6bcee3e
fix: correct URL pattern filtering for SSL Bump mode
Two issues fixed:
1. URL pattern deny rule was blocking CONNECT requests:
- The deny rule `http_access deny allowed_domains` was evaluated
for CONNECT requests, blocking SSL bump before the URL check
- Added `!CONNECT` to only deny actual HTTP requests after bump
- CONNECT requests now pass through for domain-allowed hosts
2. URL pattern regex escaping was corrupting .* wildcards:
- Input `https://api.github.com/users/.*` was becoming
`^https://api\.github\.com/users/\..*` (incorrect)
- Now preserves .* patterns using placeholder before escaping
- Output is correctly `^https://api\.github\.com/users/.*`
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>1 parent c526c6e commit 6bcee3e
2 files changed
Lines changed: 22 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
93 | 93 | | |
94 | 94 | | |
95 | 95 | | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
96 | 99 | | |
97 | 100 | | |
98 | 101 | | |
99 | | - | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
100 | 114 | | |
101 | 115 | | |
102 | 116 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
184 | 184 | | |
185 | 185 | | |
186 | 186 | | |
| 187 | + | |
| 188 | + | |
| 189 | + | |
| 190 | + | |
187 | 191 | | |
188 | 192 | | |
189 | 193 | | |
190 | 194 | | |
191 | 195 | | |
192 | 196 | | |
| 197 | + | |
| 198 | + | |
| 199 | + | |
193 | 200 | | |
194 | 201 | | |
195 | 202 | | |
| |||
0 commit comments