Repository navigation
Preserve requested HTTP with managed Chrome policies - #45
Merged
mandatoryprogrammer merged 3 commits intoOct 4, 2026
Merged
mandatoryprogrammer merged 3 commits into
mandatoryprogrammer merged 3 commits into
Conversation
Every plain-HTTP request proxied through thermoptic times out and returns a 502, regardless of the target site. Chrome's HttpsUpgrades feature silently rewrites top-level http:// navigations to https:// before making the real request. cdp.js's manual_browser_visit() registers its CDP Fetch domain interception pattern against the original http:// URL and then calls Page.navigate with that same URL, expecting Fetch.requestPaused to fire once the response comes back. Since the actual outgoing request is for the upgraded https:// URL, the interception pattern never matches, Fetch.requestPaused never fires, and the request sits until the internal timeout fires, surfacing to the client as a 502. Adding HttpsUpgrades to Chrome's --disable-features list stops the silent rewrite so the navigation matches the interception pattern and completes normally.
Owner
|
This is a really good catch that was missed because the behavior is different for localhost HTTP checks which I was doing previously, working on the fix now and will merge. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Chrome can upgrade a caller-requested HTTP navigation to HTTPS while Thermoptic waits for a response matching the original HTTP URL, eventually returning a 502 timeout. Upgrading the page used to establish an HTTP fetch context can also prevent the intended request from completing.
Install mandatory managed policies in the dedicated Chrome image:
HttpsUpgradesEnabled: falsedisables opportunistic upgrades, andHttpsOnlyMode: "disallowed"disables HTTPS-First, including strict or balanced settings retained in an existing profile. Using both supported policies covers the independent upgrade mechanisms.The image copies
chrome/policies/http_request_scheme.jsoninto Chrome's managed-policy directory. Operator instructions and the behavior change are documented in_readme/internal-notes.md; rebuild/recreate the Chrome service to apply the policy. The main README, request-handling code, dependencies, and lockfile are unchanged.Keeping caller-requested HTTP on HTTP is intentional proxy behavior and can leave traffic plaintext that Chrome would otherwise upgrade. Explicit HTTPS, certificate validation, HSTS, and server-issued redirects remain enabled. HSTS-covered HTTP URLs can still return a 307 upgrade redirect. Separately supplied Chrome instances need equivalent configuration in their own dedicated environment.
Validation
Both
docker-build (ubuntu-latest)andcompose-e2epassed onf9754ff8419f764b7ade6b31c0285a19955c6334. Successful CI run.Used existing dependencies with Node 18.20.4 and Chrome 152.0.7977.64. Real browser requests went through an isolated local forward proxy to local HTTP/HTTPS fixtures with public-style hostnames; no third-party target was required. The policy directory was mounted into isolated Chrome processes without changing the host browser's policies.
Location.net::ERR_CERT_AUTHORITY_INVALIDand Thermoptic returned 502. Trusted fixture cases used a temporary certificate-specific SPKI allowance; the certificate-rejection case ran without that allowance.chrome://policyreported both policies as Platform/Machine/Mandatory with status OK in all tested profiles.git diff --checkpassed. No dependencies were installed locally and no test files were added to the repository.The temporary verification runner used
node check.mjs fresh persisted-strict persisted-balanced untrusted-cert; it launches disposable headless Chrome processes with isolated policy mounts and profiles, serves the local fixtures, checks status/body/redirect behavior, and stops its own processes. TLS/HTTP fingerprint parity was not measured.