fix: #8 Begrenzte HTTP-Ausführungsengine im privaten Proxy implementieren #24
No reviewers
Labels
No labels
agent:done
agent:ready
agent:working
area/browser
area/cli
area/http
area/mcp
area/media
area/observability
area/proxy
area/security
area/testing
area/tunnel
priority/P0
priority/P1
priority/P2
type/chore
type/design
type/docs
type/epic
type/feature
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
ai-tools/private-proxy-mcp!24
Loading…
Reference in a new issue
No description provided.
Delete branch "agent/issue-8-begrenzte-http-ausführungsengine-im-pri"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
httptest-Abdeckung für Methoden, Redirects, Kompression, Binärdaten, 404/500, Timeout, Cancel und endlose ResponsesAlle Änderungen wurden in drei Commits gepusht.
go test ./...undgo vet ./...sind erfolgreich; der Arbeitsbaum ist sauber.Prüfe die HTTP-Engine gegen Scope und Akzeptanzkriterien; fehlende, klar abgegrenzte Punkte werden mit Tests ergänzt und jeweils direkt committed und gepusht.Die Engine deckt die isolierte Ausführung ab, ist aber noch nicht an den Tunnel-Request-Lifecycle gebunden. Ich ergänze die Ausführungsschicht so, dass Frame-Deadline und Cancel tatsächlich bis
net/httpwirken und Response-/Fehlerframes stabil erzeugt werden.Tunnel-Frames werden nun mit ihrer absoluten Deadline in einen Request-Kontext überführt; Cancel erzeugt einen terminalen Fehlerframe und schließt die laufende Upstream-Anfrage. Ein End-to-End-Test deckt diese Kette ab.Die Tunnel-Antwort wird zusätzlich auf die effektive Framegrenze begrenzt: Base64-/JSON-Overhead kann einen ansonsten zulässigen HTTP-Body nicht mehr über die 8-MiB-Framegrenze treiben.PR_TITLE: feat(http): execute bounded tunnel HTTP requestsPR_BODY: Implements and wires the bounded HTTP engine into tunnel processing, including frame deadlines, cancellation propagation, typed errors, and frame-safe Base64 response truncation. Tests pass with
go test ./....Alles Implementiert
Closes #8
🚧 WIP pull request opened — linked to issue #8. Agent is working…
💭 Agent progress
Inspecting tool call status
Ich prüfe zunächst Repository-Struktur, bestehende Tunnel-/Policy-Typen und Tests und setze die HTTP-Engine anschließend in kleinen, separat gepushten Commits um.
💭 Agent progress
Refining command execution strategy
💭 Agent progress
Inspecting protocol README file
💭 Agent progress
Designing reusable httpexec validator package
Reviewing relevant git history
💭 Agent progress
Outlining httpexec package API
Designing request and response models with limits
Planning compressed response truncation detection
Clarifying response truncation behavior
Planning header validation and redirect handling
Initiating patch application and file creation
Die bestehende Tunnel-Spezifikation setzt 6 MiB als Obergrenze und Base64 für Bodies. Ich ergänze eine eigenständige
internal/httpexec-Engine mit wiederverwendetem Transport, typisierten Protokollfehlern, Redirect-Validierung pro Hop und getrennten Limits für übertragene und dekomprimierte Antworten.💭 Agent progress
Aligning slice index syntax
💭 Agent progress
Planning test compile for race diff
💭 Agent progress
Planning comprehensive HTTP request tests
Implementing gzip limit reader improvements
Designing HTTP header validation logic
Planning test creation and patch application
💭 Agent progress
Running gofmt tests
Fixing sandbox cache location
💭 Agent progress
Fixing token parsing and test assertions
💭 Agent progress
Reviewing HTTP body size limits and truncation
Refining response body truncation with compression limits
Adding tests for endless and error responses
Die Kernfälle laufen; beim Header-Test wurde ein Map-Reihenfolgefehler sichtbar: per
Connectionbenannte Header mussten vor dem Kopieren gesammelt werden. Das ist korrigiert. Als Nächstes sichere ich unkomprimierte/endlose Responses explizit über den Truncation-Pfad ab.💭 Agent progress
Running full test suite
💭 Agent progress
Planning diff inspection and vetting
💭 Agent progress
Staging and preparing commit
Die HTTP-Engine ist jetzt vollständig durch
httptestabgedeckt, einschließlich endloser Responses; sie beendet den Upstream nach 4-KiB-Testlimit und behält nur den begrenzten Body. Ich committe und pushe diesen abgeschlossenen Kern jetzt separat.💭 Agent progress
Assessing engine proxy integration issues
Planning protocol enhancements and header limits
Refining response compression handling
Refining content-encoding handling
Implementing header selection with encoding control
Der erste Commit ist gepusht (
01f4dd0). Im zweiten Schritt ergänze ich die noch fehlende harte Response-Header-Grenze, sichere Connection-Pool-Wiederverwendung/Shutdown per Test ab und dokumentiere die erweiterten Tunnel-Response-Felder.Inspecting patch application status
💭 Agent progress
Planning smaller patches
💭 Agent progress
Testing import locations
💭 Agent progress
Applying tests
💭 Agent progress
Applying gofmt formatting
💭 Agent progress
Adding test for large response header
💭 Agent progress
Inspecting gofmt alignment diff
💭 Agent progress
Adjusting JSON indent and adding header test
💭 Agent progress
Testing header size limits
💭 Agent progress
Preparing commit and push
Pooling, Idle-Close und die 64-KiB-Response-Header-Grenze sind verifiziert; 404/500 bleiben reguläre Responses. Die Tunnel-v1-Dokumentation beschreibt jetzt finale URL, Base64-Kennzeichnung, Dauer und Truncation. Ich committe und pushe dieses Hardening separat.
💭 Agent progress
Reviewing final audit and HTTP client behaviors
Enhancing redirect URL validation and max redirects handling
Defining MaxRedirects default and validating redirects
💭 Agent progress
Running tests before pushing
Beim finalen Redirect-Audit fehlte noch die strukturelle URL-Prüfung auf Folgehops. Redirects mit Userinfo oder Fragment werden nun bereits vor der Policy-Prüfung als
policy_deniedabgewiesen.💭 Agent progress
Verifying clean commits
🔍 Verifying implementation (attempt 1/3)
💭 Agent progress
Composing concise German PR comment with tests
httptest-Abdeckung für Methoden, Redirects, Kompression, Binärdaten, 404/500, Timeout, Cancel und endlose ResponsesAlle Änderungen wurden in drei Commits gepusht.
go test ./...undgo vet ./...sind erfolgreich; der Arbeitsbaum ist sauber.Prüfe die HTTP-Engine gegen Scope und Akzeptanzkriterien; fehlende, klar abgegrenzte Punkte werden mit Tests ergänzt und jeweils direkt committed und gepusht.💭 Agent progress
Inspecting files and tests
💭 Agent progress
Assessing tunnel integration and proxy use
💭 Agent progress
Assessing tunnel lifecycle and connector integration
Clarifying proxy and connector design mismatch
Die Engine deckt die isolierte Ausführung ab, ist aber noch nicht an den Tunnel-Request-Lifecycle gebunden. Ich ergänze die Ausführungsschicht so, dass Frame-Deadline und Cancel tatsächlich bis
net/httpwirken und Response-/Fehlerframes stabil erzeugt werden.Planning Session deadline handling
Designing connection serving with executor integration
💭 Agent progress
Planning focused ExecuteProxyRequest implementation
Designing conservative tunnel connection loop
Implementing cancellation error handling
Updating deadline handling and transport loop
Refactoring listener engine injection and error handling
💭 Agent progress
Adding connector imports
💭 Agent progress
Implementing session cancellation and write flushing
💭 Agent progress
Testing shared engine creation adjustment
💭 Agent progress
Planning integration test using net.Pipe
Implementing cancellable HTTP test with httptest
💭 Agent progress
Planning concurrent tunnel test
Tunnel-Frames werden nun mit ihrer absoluten Deadline in einen Request-Kontext überführt; Cancel erzeugt einen terminalen Fehlerframe und schließt die laufende Upstream-Anfrage. Ein End-to-End-Test deckt diese Kette ab.
💭 Agent progress
Inspecting tunnel handler and payload limits
Adjusting response size limits and framing
Implementing response truncation with binary search
Implementing bounded response marshalling
Testing response size limits
💭 Agent progress
Noting frame deadline overflow risk
Checking deadline overflow and redirect defaults
Die Tunnel-Antwort wird zusätzlich auf die effektive Framegrenze begrenzt: Base64-/JSON-Overhead kann einen ansonsten zulässigen HTTP-Body nicht mehr über die 8-MiB-Framegrenze treiben.
💭 Agent progress
Committing and pushing changes
💭 Agent progress
Checking connection handling and closure logic
Verifying request body size handling and compression logic
Assessing response body decompression limits and updating docs
Clarifying handler state usage
💭 Agent progress
Inspecting unicode carriage returns
💭 Agent progress
Applying separate line break encoding
💭 Agent progress
Preparing test and committing changes
💭 Agent progress
Inspecting git status output and cancellation behavior
✅ Verify OK — agent reported Alles Implementiert
WIP: #8 Begrenzte HTTP-Ausführungsengine im privaten Proxy implementierento fix: #8 Begrenzte HTTP-Ausführungsengine im privaten Proxy implementieren✅ forge agent finished implementation
docs(http): document frame-safe truncationAgent output (tail)
⚪ No CI / build job — skipping babysit.
📊 Agent usage (
codex/ ACP)💭 Agent progress
Preparing final PR title and body
Ensuring exact PR body formatting