test(android): send Proxy-Authorization via OkHttp in auth tests - #728
Merged
Merged
Conversation
JDK-8384708 (August 2026 security update) makes HttpURLConnection strip a user-set Proxy-Authorization header from non-proxied connections, so six tests reached HttpServer without a token and got 407 on patched JDKs. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
XCFramework BuildThis PR's XCFramework is available for testing. Add the following to your .package(url: "https://github.com/wordpress-mobile/GutenbergKit", branch: "pr-build/728")Built from 4026103 |
Contributor
|
@dcalhoun Claude had these findings, the first of which sounds valid.
|
OkHttp throws on a 407 from a direct connection, so it couldn't carry the wrong-token or oversized tests, which still used HttpURLConnection. The wrong-token test passed without sending its token on patched JDKs. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
A null status line otherwise surfaced as a bare NPE from split(). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Member
Author
|
Thanks for sharing these, @nbradbury. I believe I addressed each in ee32019. I also had Claude check each test for false positives. Ready for another review. |
Contributor
|
@dcalhoun As with #729, Claude found some issues but again I feel it sometimes just looks for trouble. I'll approve this and leave Claude's findings for you to peruse.
|
The socket timeout matched the server's 5s idle timeout, so a drain-before-auth regression failed as either a 408 or a client timeout depending on which fired first. Waiting longer makes it fail as 407 vs 408. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Member
Author
|
Addressed the timeout overlap in 4026103. The rest appear pre-existing or quite low impact. Sharing the raw-socket helper with |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What?
Ensure
Proxy-Authorizationheader is sent with auth test requests.Why?
The unexpected absence led to test failures in newer, patched JDK versions. Currently only occurring locally.
How?
Rely upon a raw socket server in the auth tests.
Testing Instructions
Run
test/android-robolectric-sdk-propertieslocally when using a patched JDK version.Accessibility Testing Instructions
N/A, no user-facing changes.
Screenshots or screencast
N/A, no user-facing changes.
AI-generated details
Problem: On a patched JDK (e.g. 21.0.12),
make test-android-library-unitfails sixHttpServerAuthenticationTestswithexpected:<200> but was:<407>. CI passes only because its JVM predates the fix. It will fail the same way once CI picks up a patched JDK.Cause: The August 2026 JDK security update JDK-8384708 (also backported to JDK 17) makes
HttpURLConnectionremove any user-setProxy-Authorizationheader when the connection doesn't use a proxy. The token never reachesHttpServer, which correctly answers 407. Production code is unaffected: it never sendsProxy-AuthorizationthroughHttpURLConnection.Fix: Every test that sends
Proxy-Authorizationnow uses a raw-socket helper, so the test controls the exact bytes sent. This also fixes "request with wrong token returns 407", which passed on patched JDKs without ever sending its token. OkHttp was tried first but throws on a 407 from a direct connection. Each test was checked by breaking the matching server behavior (accepting any token, ignoringProxy-Authorization, case-sensitive scheme, reversed header precedence, reading an oversized body before auth, and so on) and confirming it fails.Testing:
make test-android-library-unit(on JDK 21.0.12+ or an equally patched 17.x)HttpServerAuthenticationTestspass.🤖 Generated with Claude Code