Skip to content

added proxyConnectCb (#870)#871

Closed
wolfkor wants to merge 12 commits into
nats-io:mainfrom
wolfkor:fix-870
Closed

added proxyConnectCb (#870)#871
wolfkor wants to merge 12 commits into
nats-io:mainfrom
wolfkor:fix-870

Conversation

@wolfkor

@wolfkor wolfkor commented Apr 19, 2025

Copy link
Copy Markdown
Contributor

add proxyConnectCb for TLS connection via proxy (#870)

@mtmk

mtmk commented Apr 22, 2025

Copy link
Copy Markdown
Member

for context @wolfkor helped us adding this feature to .NET client nats-io/nats.net#826 I'm assuming this is to implement the same here. I think the idea here has lots of potential even though the main use case now is to punch through (probably corporate) proxies. It sounds good to me in general. I shall leave it to @levb and @kozlovic if it's something they want to consider.

@wolfkor

wolfkor commented Jul 19, 2025

Copy link
Copy Markdown
Contributor Author

It's a pity that nothing is happening here @kozlovic

@kozlovic kozlovic left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry for the delay. I am not certain of the intended use-case, so I would need more information about how you plan to use that. Also, we would really need to add some tests (for instance provide a callback that returns an error and verify that connection fails), and one callback that does create socket ok. If you don't know how to add a test, I could add it after merging (if we accept the PR once we resolve the issues). Thanks!

Comment thread src/comsock.c Outdated
Comment thread src/comsock.c Outdated
Comment thread src/comsock.c Outdated
Comment thread src/conn.c Outdated
Comment thread src/nats.h Outdated
Comment thread src/nats.h Outdated
@wolfkor

wolfkor commented Jul 26, 2025

Copy link
Copy Markdown
Contributor Author

After wasting my time with these damned formatting issues, i will write the test another day

@wolfkor
wolfkor requested a review from kozlovic July 27, 2025 11:33
kozlovic pushed a commit that referenced this pull request Jul 28, 2025
Based from PR #871 that had formatting and test issues.

Resolves #870
@kozlovic

Copy link
Copy Markdown
Member

@wolfkor I am going to close this PR and I have submitted PR #897 that fixes formatting issues and the test (and some little changes). I have used your previous commits and squashed them into one and then added a commit with my changes. You are mentioned as the author of the PR. I hope this approach is ok (I think it would have been painful for both of us to have you make the formatting changes in your PR with your current editor settings). Thanks!

@kozlovic kozlovic closed this Jul 28, 2025
@wolfkor
wolfkor deleted the fix-870 branch July 29, 2025 20:05
kozlovic added a commit that referenced this pull request Sep 26, 2025
Release notes will be:

This release contains some breaking changes. See the "Changed" section below.

* Build
  * Disable NATS Streaming by default by @mtmk in #770
  * TLS
    * Require OpenSSL 1.1.1+ to compile. Removed the `NATS_BUILD_TLS_USE_OPENSSL_1_1_API` CMake variable by @kozlovic in #905
    * The option `natsOptions_SetSSLVerificationCallback` signature was changed to replace the use of `SSL_verify_cb` (which required OpenSSL dependency in the `nats.h` file), to the new callback `natsSSLVerifyCb`. See documentation of `natsSSLVerifyCb` to see the cast needed to compile with this new header file by @kozlovic in #908
* Modification of a `natsOptions` object if it has TLS/SSL configuration and is actively used by connections will now return a `NATS_ILLEGAL_STATE` by @kozlovic in #912

* Options
  * Ability to load the trusted CA certificates from a directory using the new option `natsOptions_LoadCATrustedCertificatesPath` by @kerbert101 in #862
  * Ability to connect via HTTP proxy for instance by adding a proxy connection handler using the new option `natsOptions_SetProxyConnHandler` by @wolfkor in #871 and @kozlovic in #897
  * Ability to load the certificate chain and key from a file on every connection attempt using the new option `natsOptions_LoadCertificatesChainDynamic` by @Matus-p in #901
  * Ability to perform concurrent TLS handshakes that may improve time it takes for concurrent connections to be established using the new option `natsOptions_AllowConcurrentTLSHandshakes ` by @kozlovic in #914. Issue was reported by @yanyongcheng in #899
* JetStream
  * Per-message TTL support (a NATS Server v2.11 feature) by @levb in #863
  * Pull consumer priority groups (a NATS Server v2.11 feature) by @levb in #869
* ObjectStore support by @kozlovic in #902. Thanks to @jfflynn41 and @alex1891 for the feedback in #876

* JetStream
  * Handling of publish asynchronous timeouts by @kozlovic in #886. Issue reported by @yanyongcheng in #880
* Timer insertion by @kozlovic in #883. Issue reported by @yanyongcheng in #881

* EventLoop:
  * Handling of possible failure on initial attach by @kozlovic in #918
  * LibEvent: `natsConnection_Close()` not closing the TCP connection by @kozlovic in #882. Issue was reported by @yanyongcheng in #879
  * Libuv: Possible crash if connection is destroyed while receiving data by @kozlovic in #889. Issue was reported by @yanyongcheng in #888
* KeyValue
  * Keys, History or watcher's next may incorrectly return `NATS_TIMEOUT` by @kozlovic in #917/ Issue was reported by @ArashPartow in #916
* MicroServices:
  * Wrong marshaling of `average_processing_time` by @kozlovic in #892. Issue was reported by @Archie3d in #890
  * Statistics error was always incremented by @kozlovic in #894. Issue was reported by @Archie3d in #893
* TLS
  * Unknown type name `SSL_verify_cb` by @kozlovic in #878. Issue was reported by @philipfoulkes in #877
  * Initialization and cleanup code related to OpenSSL was removed since it was deprecated for versions post OpenSSL 1.1. A cleanup function pertinent to 1.1+ code was possibly causing a problem. By @kozlovic in #905. Issue was reported by @vdeters in #904
  * Possible hang during handshake by @kozlovic in #907. Issue was reported by @etrochim in #906
  * Protect calls to `SSL_read` and `SSL_write` with a mutex. Since the same `SSL` object is shared between different threads, the OpenSSL library requires a mutex to be used by @kozlovic in #913
* Memory allocation check by @wooffie in #868
* Add missing status text string by @oldnick85 in #872 and @kozlovic in #874 (the issue was not present in any published release and was introduced in #869)
* Parsing of message headers with `NULL` or all-whitespace values by @habbbe in #873
* Removed some unused code related to handling of responses and added custom inbox with very long prefix test by @kozlovic in #885. Issue was reported by @yanyongcheng in #884
* Connection drain could cause missed reply and/or a 100ms delay by @kozlovic in #915. Issue was reported by @T-Maxxx in #911

* Build
  * Deprecated Ubuntu 20.04 in GitHub actions by @levb in #864
  * Removed the older compiler jobs by @levb in #865
  * Fixed Windows build to use the NATS Server main branch by @levb in #866

* @kerbert101 made their first contribution in #862
* @habbbe made their first contribution in #873
* @wolfkor made their first contribution in #871
* @Matus-p made their first contribution in #901

Signed-off-by: Ivan Kozlovic <ivan@synadia.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants