mirror of
https://github.com/only-cli/oc.git
synced 2026-09-15 10:40:56 +02:00
The feature landed with one sentence in the install paragraph, which named the three environment variables and nothing else. Anyone actually putting oc behind a corporate proxy had to read src/fetch.js to learn that an https target prefers HTTPS_PROXY and falls back to HTTP_PROXY while an http target uses HTTP_PROXY only, that a bare host:port is read as http://, that a socks URL is refused rather than ignored, or that NO_PROXY takes suffix, wildcard, host:port, and CIDR entries. All of that is now in a Proxies section, and every claim in it was checked against the merged code rather than written from the diff. Two limits are documented instead of left to be discovered. oc does not read ALL_PROXY, but the impers transport is libcurl underneath and reads it on its own, so a request oc treats as direct can still leave through a proxy; the same holds for the *.suffix, host:port, and CIDR forms of NO_PROXY, which libcurl does not parse. Verified live against a third party proxy by watching the egress IP: with only ALL_PROXY set, or with NO_PROXY=*.host naming the target, oc reported a direct fetch and the request went through the proxy anyway. And an IPv6 literal over HTTPS cannot work through a proxy today, because URL.hostname keeps the brackets, so net.isIP reads 0 and the SNI and certificate check both treat [2606:...] as a DNS name. The security properties a reader would otherwise have to assume are stated: the CONNECT tunnel still verifies the origin certificate (confirmed against expired, self-signed, and wrong-host endpoints through a real proxy), credentials in the proxy URL reach the proxy and nothing else including across redirects, private and internal targets stay refused, and a name that resolves publicly for oc and internally for the proxy is not something oc can detect, so the proxy is trusted for its own egress policy. The skill gets the short version, since an agent needs two things: that no flag or setup is required, and that a "proxy failed" or "blocked" line is a transport problem to report rather than a page to retry. llms.txt gets one fact next to the existing transport fact.