Files
CLIProxyAPI/internal/runtime/executor/helps/proxy_helpers.go
Luis Pater d582067c06 feat(executor): support execution-scoped request proxy overrides
- Add context helpers to manage execution-scoped proxy overrides
- Prioritize request proxy over credential and global proxy settings across HTTP and uTLS clients
- Propagate request proxy in conductor execution and plugin host adapters
- Isolate Codex WebSocket connection reuse by proxy endpoint

Closes: #6013
2026-09-22 03:54:34 +08:00

158 lines
4.9 KiB
Go

package helps
import (
"context"
"fmt"
"net/http"
"strings"
"time"
"github.com/router-for-me/CLIProxyAPI/v7/internal/config"
cliproxyauth "github.com/router-for-me/CLIProxyAPI/v7/sdk/cliproxy/auth"
cliproxyexecutor "github.com/router-for-me/CLIProxyAPI/v7/sdk/cliproxy/executor"
"github.com/router-for-me/CLIProxyAPI/v7/sdk/proxyutil"
log "github.com/sirupsen/logrus"
)
// NewProxyAwareHTTPClient creates an HTTP client with proper proxy configuration priority:
// 1. Use the execution-scoped request proxy if configured (highest priority)
// 2. Use auth.ProxyURL if configured
// 3. Use cfg.ProxyURL if auth proxy is not configured
// 4. Use RoundTripper from context if none are configured
//
// Parameters:
// - ctx: The context containing optional RoundTripper
// - cfg: The application configuration
// - auth: The authentication information
// - timeout: The client timeout (0 means no timeout)
//
// Returns:
// - *http.Client: An HTTP client with configured proxy or transport
func NewProxyAwareHTTPClient(ctx context.Context, cfg *config.Config, auth *cliproxyauth.Auth, timeout time.Duration) *http.Client {
httpClient := &http.Client{}
if timeout > 0 {
httpClient.Timeout = timeout
}
// Priority: request override, then auth.ProxyURL, then cfg.ProxyURL.
proxyURL := effectiveProxyURL(ctx, cfg, auth)
// If we have a proxy URL configured, set up the transport
if proxyURL != "" {
transport := buildProxyTransport(proxyURL)
if transport != nil {
httpClient.Transport = transport
return httpClient
}
// If proxy setup failed, log and fall through to context RoundTripper
log.Debugf("failed to setup proxy from URL: %s, falling back to context transport", proxyutil.Redact(proxyURL))
}
// Priority 3: Use RoundTripper from context (typically from RoundTripperFor)
if rt, ok := ctx.Value("cliproxy.roundtripper").(http.RoundTripper); ok && rt != nil {
httpClient.Transport = rt
}
return httpClient
}
var devinTransportCache = NewTransportCache[string](DefaultTransportCacheCapacity)
// NewDevinHTTPClient creates an HTTP client customized for Devin Connect-RPC upstream.
// Suppresses automatic Accept-Encoding: gzip while preserving connection reuse across requests.
func NewDevinHTTPClient(ctx context.Context, cfg *config.Config, auth *cliproxyauth.Auth, timeout time.Duration) *http.Client {
// A request proxy replaces both the injected round tripper and credential/global proxy.
// Respect explicitly injected context RoundTripper only when no request override is set.
if cliproxyexecutor.RequestProxyURL(ctx) == "" && ctx != nil {
if rt, ok := ctx.Value("cliproxy.roundtripper").(http.RoundTripper); ok && rt != nil {
if tr, ok := rt.(*http.Transport); ok {
key := fmt.Sprintf("rt:%p", tr)
cloned, err := devinTransportCache.Get(key, func() (*http.Transport, error) {
c := tr.Clone()
c.DisableCompression = true
return c, nil
})
if err == nil && cloned != nil {
return &http.Client{
Transport: cloned,
Timeout: timeout,
}
}
}
return &http.Client{
Transport: devinNoGzipRoundTripper{base: rt},
Timeout: timeout,
}
}
}
proxyURL := effectiveProxyURL(ctx, cfg, auth)
tr, err := devinTransportCache.Get(proxyURL, func() (*http.Transport, error) {
var base *http.Transport
if proxyURL != "" {
base = buildProxyTransport(proxyURL)
}
if base == nil {
if dt, ok := http.DefaultTransport.(*http.Transport); ok {
base = dt.Clone()
} else {
base = &http.Transport{}
}
}
base.DisableCompression = true
return base, nil
})
if err != nil || tr == nil {
tr = &http.Transport{DisableCompression: true}
}
return &http.Client{
Transport: tr,
Timeout: timeout,
}
}
type devinNoGzipRoundTripper struct {
base http.RoundTripper
}
func (rt devinNoGzipRoundTripper) RoundTrip(req *http.Request) (*http.Response, error) {
if req.Header.Get("Accept-Encoding") == "" {
req.Header.Set("Accept-Encoding", "identity")
}
return rt.base.RoundTrip(req)
}
func effectiveProxyURL(ctx context.Context, cfg *config.Config, auth *cliproxyauth.Auth) string {
if proxyURL := cliproxyexecutor.RequestProxyURL(ctx); proxyURL != "" {
return proxyURL
}
if auth != nil {
if proxyURL := strings.TrimSpace(auth.ProxyURL); proxyURL != "" {
return proxyURL
}
}
if cfg != nil {
return strings.TrimSpace(cfg.ProxyURL)
}
return ""
}
// buildProxyTransport creates an HTTP transport configured for the given proxy URL.
// It supports SOCKS5, HTTP, and HTTPS proxy protocols.
//
// Parameters:
// - proxyURL: The proxy URL string (e.g., "socks5://user:pass@host:port", "http://host:port")
//
// Returns:
// - *http.Transport: A configured transport, or nil if the proxy URL is invalid
func buildProxyTransport(proxyURL string) *http.Transport {
transport, _, errBuild := proxyutil.BuildHTTPTransport(proxyURL)
if errBuild != nil {
log.Errorf("%v", errBuild)
return nil
}
return transport
}