Skip to content

fix: add explicit default auth challenge handling to SessionDelegate - #51

Merged
Recouse merged 1 commit into
Recouse:mainfrom
liefran-sim:fix/add-default-auth-challenge-handling
May 14, 2026
Merged

fix: add explicit default auth challenge handling to SessionDelegate#51
Recouse merged 1 commit into
Recouse:mainfrom
liefran-sim:fix/add-default-auth-challenge-handling

Conversation

@liefran-sim

Copy link
Copy Markdown
Contributor

Summary

  • Adds urlSession(_:didReceive challenge:completionHandler:) to SessionDelegate with .performDefaultHandling
  • Fixes SSE connections silently failing when going through MITM proxies (mitmproxy, Charles Proxy, etc.)

Closes#50

Problem

When using EventSource through an MITM proxy with a trusted CA certificate installed at the OS level, SSE connections fail silently. The request never reaches the proxy and no error events are emitted.

SessionDelegate implements URLSessionDataDelegate but does not implement the authentication challenge delegate method. While URLSession should fall back to default system trust evaluation, in practice this can cause connections to be silently rejected when a custom delegate is present without explicit challenge handling.

Fix

Add explicit .performDefaultHandling to SessionDelegate:

func urlSession(
_ session:URLSession,
didReceive challenge:URLAuthenticationChallenge,
completionHandler:@escaping(URLSession.AuthChallengeDisposition,URLCredential?)->Void){completionHandler(.performDefaultHandling,nil)}

This explicitly delegates to the system's default trust evaluation, which correctly respects user-installed CA certificates. This has no effect on normal (non-proxy) connections — it simply makes the default behavior explicit rather than implicit.

@liefran-sim
liefran-sim requested a review from Recouse as a code ownerMay 11, 2026 04:11
Without implementing urlSession(_:didReceive challenge:), URLSession
may silently reject server certificates in certain proxy/MITM scenarios
(e.g., mitmproxy, Charles Proxy) even when the CA certificate is
installed and trusted at the OS level.
Adding explicit .performDefaultHandling ensures the system's default
trust evaluation is used, which correctly respects user-installed CA
certificates. This has no effect on normal (non-proxy) connections.
@liefran-sim
liefran-simforce-pushed the fix/add-default-auth-challenge-handling branch from f962b84 to 47b2713CompareMay 11, 2026 04:42

@RecouseRecouse left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi,
Thanks for the PR!

I’ll accept it, but in the future, it would be good to support custom authentication, similar to the approach used in #47.

@Recouse
Recouse merged commit dcdd880 into Recouse:mainMay 14, 2026
3 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SSE connections fail silently through MITM proxies (missing auth challenge delegate)

2 participants

@liefran-sim@Recouse
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
fix: add explicit default auth challenge handling to SessionDelegate by liefran-sim · Pull Request #51 · Recouse/EventSource · GitHub
Skip to content

fix: add explicit default auth challenge handling to SessionDelegate - #51

Merged
Recouse merged 1 commit into
Recouse:mainfrom
liefran-sim:fix/add-default-auth-challenge-handling
May 14, 2026
Merged

fix: add explicit default auth challenge handling to SessionDelegate#51
Recouse merged 1 commit into
Recouse:mainfrom
liefran-sim:fix/add-default-auth-challenge-handling

Conversation

@liefran-sim

Copy link
Copy Markdown
Contributor

Summary

  • Adds urlSession(_:didReceive challenge:completionHandler:) to SessionDelegate with .performDefaultHandling
  • Fixes SSE connections silently failing when going through MITM proxies (mitmproxy, Charles Proxy, etc.)

Closes#50

Problem

When using EventSource through an MITM proxy with a trusted CA certificate installed at the OS level, SSE connections fail silently. The request never reaches the proxy and no error events are emitted.

SessionDelegate implements URLSessionDataDelegate but does not implement the authentication challenge delegate method. While URLSession should fall back to default system trust evaluation, in practice this can cause connections to be silently rejected when a custom delegate is present without explicit challenge handling.

Fix

Add explicit .performDefaultHandling to SessionDelegate:

func urlSession(
_ session:URLSession,
didReceive challenge:URLAuthenticationChallenge,
completionHandler:@escaping(URLSession.AuthChallengeDisposition,URLCredential?)->Void){completionHandler(.performDefaultHandling,nil)}

This explicitly delegates to the system's default trust evaluation, which correctly respects user-installed CA certificates. This has no effect on normal (non-proxy) connections — it simply makes the default behavior explicit rather than implicit.

@liefran-sim
liefran-sim requested a review from Recouse as a code ownerMay 11, 2026 04:11
Without implementing urlSession(_:didReceive challenge:), URLSession
may silently reject server certificates in certain proxy/MITM scenarios
(e.g., mitmproxy, Charles Proxy) even when the CA certificate is
installed and trusted at the OS level.
Adding explicit .performDefaultHandling ensures the system's default
trust evaluation is used, which correctly respects user-installed CA
certificates. This has no effect on normal (non-proxy) connections.
@liefran-sim
liefran-simforce-pushed the fix/add-default-auth-challenge-handling branch from f962b84 to 47b2713CompareMay 11, 2026 04:42

@RecouseRecouse left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi,
Thanks for the PR!

I’ll accept it, but in the future, it would be good to support custom authentication, similar to the approach used in #47.

@Recouse
Recouse merged commit dcdd880 into Recouse:mainMay 14, 2026
3 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SSE connections fail silently through MITM proxies (missing auth challenge delegate)

2 participants

@liefran-sim@Recouse
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix: add explicit default auth challenge handling to SessionDelegate by liefran-sim · Pull Request #51 · Recouse/EventSource · GitHub
Skip to content

fix: add explicit default auth challenge handling to SessionDelegate - #51

Merged
Recouse merged 1 commit into
Recouse:mainfrom
liefran-sim:fix/add-default-auth-challenge-handling
May 14, 2026
Merged

fix: add explicit default auth challenge handling to SessionDelegate#51
Recouse merged 1 commit into
Recouse:mainfrom
liefran-sim:fix/add-default-auth-challenge-handling

Conversation

@liefran-sim

Copy link
Copy Markdown
Contributor

Summary

  • Adds urlSession(_:didReceive challenge:completionHandler:) to SessionDelegate with .performDefaultHandling
  • Fixes SSE connections silently failing when going through MITM proxies (mitmproxy, Charles Proxy, etc.)

Closes#50

Problem

When using EventSource through an MITM proxy with a trusted CA certificate installed at the OS level, SSE connections fail silently. The request never reaches the proxy and no error events are emitted.

SessionDelegate implements URLSessionDataDelegate but does not implement the authentication challenge delegate method. While URLSession should fall back to default system trust evaluation, in practice this can cause connections to be silently rejected when a custom delegate is present without explicit challenge handling.

Fix

Add explicit .performDefaultHandling to SessionDelegate:

func urlSession(
_ session:URLSession,
didReceive challenge:URLAuthenticationChallenge,
completionHandler:@escaping(URLSession.AuthChallengeDisposition,URLCredential?)->Void){completionHandler(.performDefaultHandling,nil)}

This explicitly delegates to the system's default trust evaluation, which correctly respects user-installed CA certificates. This has no effect on normal (non-proxy) connections — it simply makes the default behavior explicit rather than implicit.

@liefran-sim
liefran-sim requested a review from Recouse as a code ownerMay 11, 2026 04:11
Without implementing urlSession(_:didReceive challenge:), URLSession
may silently reject server certificates in certain proxy/MITM scenarios
(e.g., mitmproxy, Charles Proxy) even when the CA certificate is
installed and trusted at the OS level.
Adding explicit .performDefaultHandling ensures the system's default
trust evaluation is used, which correctly respects user-installed CA
certificates. This has no effect on normal (non-proxy) connections.
@liefran-sim
liefran-simforce-pushed the fix/add-default-auth-challenge-handling branch from f962b84 to 47b2713CompareMay 11, 2026 04:42

@RecouseRecouse left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi,
Thanks for the PR!

I’ll accept it, but in the future, it would be good to support custom authentication, similar to the approach used in #47.

@Recouse
Recouse merged commit dcdd880 into Recouse:mainMay 14, 2026
3 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SSE connections fail silently through MITM proxies (missing auth challenge delegate)

2 participants

@liefran-sim@Recouse
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix: add explicit default auth challenge handling to SessionDelegate by liefran-sim · Pull Request #51 · Recouse/EventSource · GitHub
Skip to content

fix: add explicit default auth challenge handling to SessionDelegate - #51

Merged
Recouse merged 1 commit into
Recouse:mainfrom
liefran-sim:fix/add-default-auth-challenge-handling
May 14, 2026
Merged

fix: add explicit default auth challenge handling to SessionDelegate#51
Recouse merged 1 commit into
Recouse:mainfrom
liefran-sim:fix/add-default-auth-challenge-handling

Conversation

@liefran-sim

Copy link
Copy Markdown
Contributor

Summary

  • Adds urlSession(_:didReceive challenge:completionHandler:) to SessionDelegate with .performDefaultHandling
  • Fixes SSE connections silently failing when going through MITM proxies (mitmproxy, Charles Proxy, etc.)

Closes#50

Problem

When using EventSource through an MITM proxy with a trusted CA certificate installed at the OS level, SSE connections fail silently. The request never reaches the proxy and no error events are emitted.

SessionDelegate implements URLSessionDataDelegate but does not implement the authentication challenge delegate method. While URLSession should fall back to default system trust evaluation, in practice this can cause connections to be silently rejected when a custom delegate is present without explicit challenge handling.

Fix

Add explicit .performDefaultHandling to SessionDelegate:

func urlSession(
_ session:URLSession,
didReceive challenge:URLAuthenticationChallenge,
completionHandler:@escaping(URLSession.AuthChallengeDisposition,URLCredential?)->Void){completionHandler(.performDefaultHandling,nil)}

This explicitly delegates to the system's default trust evaluation, which correctly respects user-installed CA certificates. This has no effect on normal (non-proxy) connections — it simply makes the default behavior explicit rather than implicit.

@liefran-sim
liefran-sim requested a review from Recouse as a code ownerMay 11, 2026 04:11
Without implementing urlSession(_:didReceive challenge:), URLSession
may silently reject server certificates in certain proxy/MITM scenarios
(e.g., mitmproxy, Charles Proxy) even when the CA certificate is
installed and trusted at the OS level.
Adding explicit .performDefaultHandling ensures the system's default
trust evaluation is used, which correctly respects user-installed CA
certificates. This has no effect on normal (non-proxy) connections.
@liefran-sim
liefran-simforce-pushed the fix/add-default-auth-challenge-handling branch from f962b84 to 47b2713CompareMay 11, 2026 04:42

@RecouseRecouse left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi,
Thanks for the PR!

I’ll accept it, but in the future, it would be good to support custom authentication, similar to the approach used in #47.

@Recouse
Recouse merged commit dcdd880 into Recouse:mainMay 14, 2026
3 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SSE connections fail silently through MITM proxies (missing auth challenge delegate)

2 participants

@liefran-sim@Recouse
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' fix: add explicit default auth challenge handling to SessionDelegate by liefran-sim · Pull Request #51 · Recouse/EventSource · GitHub
Skip to content

fix: add explicit default auth challenge handling to SessionDelegate - #51

Merged
Recouse merged 1 commit into
Recouse:mainfrom
liefran-sim:fix/add-default-auth-challenge-handling
May 14, 2026
Merged

fix: add explicit default auth challenge handling to SessionDelegate#51
Recouse merged 1 commit into
Recouse:mainfrom
liefran-sim:fix/add-default-auth-challenge-handling

Conversation

@liefran-sim

Copy link
Copy Markdown
Contributor

Summary

  • Adds urlSession(_:didReceive challenge:completionHandler:) to SessionDelegate with .performDefaultHandling
  • Fixes SSE connections silently failing when going through MITM proxies (mitmproxy, Charles Proxy, etc.)

Closes#50

Problem

When using EventSource through an MITM proxy with a trusted CA certificate installed at the OS level, SSE connections fail silently. The request never reaches the proxy and no error events are emitted.

SessionDelegate implements URLSessionDataDelegate but does not implement the authentication challenge delegate method. While URLSession should fall back to default system trust evaluation, in practice this can cause connections to be silently rejected when a custom delegate is present without explicit challenge handling.

Fix

Add explicit .performDefaultHandling to SessionDelegate:

func urlSession(
_ session:URLSession,
didReceive challenge:URLAuthenticationChallenge,
completionHandler:@escaping(URLSession.AuthChallengeDisposition,URLCredential?)->Void){completionHandler(.performDefaultHandling,nil)}

This explicitly delegates to the system's default trust evaluation, which correctly respects user-installed CA certificates. This has no effect on normal (non-proxy) connections — it simply makes the default behavior explicit rather than implicit.

@liefran-sim
liefran-sim requested a review from Recouse as a code ownerMay 11, 2026 04:11
Without implementing urlSession(_:didReceive challenge:), URLSession
may silently reject server certificates in certain proxy/MITM scenarios
(e.g., mitmproxy, Charles Proxy) even when the CA certificate is
installed and trusted at the OS level.
Adding explicit .performDefaultHandling ensures the system's default
trust evaluation is used, which correctly respects user-installed CA
certificates. This has no effect on normal (non-proxy) connections.
@liefran-sim
liefran-simforce-pushed the fix/add-default-auth-challenge-handling branch from f962b84 to 47b2713CompareMay 11, 2026 04:42

@RecouseRecouse left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi,
Thanks for the PR!

I’ll accept it, but in the future, it would be good to support custom authentication, similar to the approach used in #47.

@Recouse
Recouse merged commit dcdd880 into Recouse:mainMay 14, 2026
3 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SSE connections fail silently through MITM proxies (missing auth challenge delegate)

2 participants

@liefran-sim@Recouse
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix: add explicit default auth challenge handling to SessionDelegate by liefran-sim · Pull Request #51 · Recouse/EventSource · GitHub
Skip to content

fix: add explicit default auth challenge handling to SessionDelegate - #51

Merged
Recouse merged 1 commit into
Recouse:mainfrom
liefran-sim:fix/add-default-auth-challenge-handling
May 14, 2026
Merged

fix: add explicit default auth challenge handling to SessionDelegate#51
Recouse merged 1 commit into
Recouse:mainfrom
liefran-sim:fix/add-default-auth-challenge-handling

Conversation

@liefran-sim

Copy link
Copy Markdown
Contributor

Summary

  • Adds urlSession(_:didReceive challenge:completionHandler:) to SessionDelegate with .performDefaultHandling
  • Fixes SSE connections silently failing when going through MITM proxies (mitmproxy, Charles Proxy, etc.)

Closes#50

Problem

When using EventSource through an MITM proxy with a trusted CA certificate installed at the OS level, SSE connections fail silently. The request never reaches the proxy and no error events are emitted.

SessionDelegate implements URLSessionDataDelegate but does not implement the authentication challenge delegate method. While URLSession should fall back to default system trust evaluation, in practice this can cause connections to be silently rejected when a custom delegate is present without explicit challenge handling.

Fix

Add explicit .performDefaultHandling to SessionDelegate:

func urlSession(
_ session:URLSession,
didReceive challenge:URLAuthenticationChallenge,
completionHandler:@escaping(URLSession.AuthChallengeDisposition,URLCredential?)->Void){completionHandler(.performDefaultHandling,nil)}

This explicitly delegates to the system's default trust evaluation, which correctly respects user-installed CA certificates. This has no effect on normal (non-proxy) connections — it simply makes the default behavior explicit rather than implicit.

@liefran-sim
liefran-sim requested a review from Recouse as a code ownerMay 11, 2026 04:11
Without implementing urlSession(_:didReceive challenge:), URLSession
may silently reject server certificates in certain proxy/MITM scenarios
(e.g., mitmproxy, Charles Proxy) even when the CA certificate is
installed and trusted at the OS level.
Adding explicit .performDefaultHandling ensures the system's default
trust evaluation is used, which correctly respects user-installed CA
certificates. This has no effect on normal (non-proxy) connections.
@liefran-sim
liefran-simforce-pushed the fix/add-default-auth-challenge-handling branch from f962b84 to 47b2713CompareMay 11, 2026 04:42

@RecouseRecouse left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi,
Thanks for the PR!

I’ll accept it, but in the future, it would be good to support custom authentication, similar to the approach used in #47.

@Recouse
Recouse merged commit dcdd880 into Recouse:mainMay 14, 2026
3 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SSE connections fail silently through MITM proxies (missing auth challenge delegate)

2 participants

@liefran-sim@Recouse
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix: add explicit default auth challenge handling to SessionDelegate by liefran-sim · Pull Request #51 · Recouse/EventSource · GitHub
Skip to content

fix: add explicit default auth challenge handling to SessionDelegate - #51

Merged
Recouse merged 1 commit into
Recouse:mainfrom
liefran-sim:fix/add-default-auth-challenge-handling
May 14, 2026
Merged

fix: add explicit default auth challenge handling to SessionDelegate#51
Recouse merged 1 commit into
Recouse:mainfrom
liefran-sim:fix/add-default-auth-challenge-handling

Conversation

@liefran-sim

Copy link
Copy Markdown
Contributor

Summary

  • Adds urlSession(_:didReceive challenge:completionHandler:) to SessionDelegate with .performDefaultHandling
  • Fixes SSE connections silently failing when going through MITM proxies (mitmproxy, Charles Proxy, etc.)

Closes#50

Problem

When using EventSource through an MITM proxy with a trusted CA certificate installed at the OS level, SSE connections fail silently. The request never reaches the proxy and no error events are emitted.

SessionDelegate implements URLSessionDataDelegate but does not implement the authentication challenge delegate method. While URLSession should fall back to default system trust evaluation, in practice this can cause connections to be silently rejected when a custom delegate is present without explicit challenge handling.

Fix

Add explicit .performDefaultHandling to SessionDelegate:

func urlSession(
_ session:URLSession,
didReceive challenge:URLAuthenticationChallenge,
completionHandler:@escaping(URLSession.AuthChallengeDisposition,URLCredential?)->Void){completionHandler(.performDefaultHandling,nil)}

This explicitly delegates to the system's default trust evaluation, which correctly respects user-installed CA certificates. This has no effect on normal (non-proxy) connections — it simply makes the default behavior explicit rather than implicit.

@liefran-sim
liefran-sim requested a review from Recouse as a code ownerMay 11, 2026 04:11
Without implementing urlSession(_:didReceive challenge:), URLSession
may silently reject server certificates in certain proxy/MITM scenarios
(e.g., mitmproxy, Charles Proxy) even when the CA certificate is
installed and trusted at the OS level.
Adding explicit .performDefaultHandling ensures the system's default
trust evaluation is used, which correctly respects user-installed CA
certificates. This has no effect on normal (non-proxy) connections.
@liefran-sim
liefran-simforce-pushed the fix/add-default-auth-challenge-handling branch from f962b84 to 47b2713CompareMay 11, 2026 04:42

@RecouseRecouse left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi,
Thanks for the PR!

I’ll accept it, but in the future, it would be good to support custom authentication, similar to the approach used in #47.

@Recouse
Recouse merged commit dcdd880 into Recouse:mainMay 14, 2026
3 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SSE connections fail silently through MITM proxies (missing auth challenge delegate)

2 participants

@liefran-sim@Recouse
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); fix: add explicit default auth challenge handling to SessionDelegate by liefran-sim · Pull Request #51 · Recouse/EventSource · GitHub
Skip to content

fix: add explicit default auth challenge handling to SessionDelegate - #51

Merged
Recouse merged 1 commit into
Recouse:mainfrom
liefran-sim:fix/add-default-auth-challenge-handling
May 14, 2026
Merged

fix: add explicit default auth challenge handling to SessionDelegate#51
Recouse merged 1 commit into
Recouse:mainfrom
liefran-sim:fix/add-default-auth-challenge-handling

Conversation

@liefran-sim

Copy link
Copy Markdown
Contributor

Summary

  • Adds urlSession(_:didReceive challenge:completionHandler:) to SessionDelegate with .performDefaultHandling
  • Fixes SSE connections silently failing when going through MITM proxies (mitmproxy, Charles Proxy, etc.)

Closes#50

Problem

When using EventSource through an MITM proxy with a trusted CA certificate installed at the OS level, SSE connections fail silently. The request never reaches the proxy and no error events are emitted.

SessionDelegate implements URLSessionDataDelegate but does not implement the authentication challenge delegate method. While URLSession should fall back to default system trust evaluation, in practice this can cause connections to be silently rejected when a custom delegate is present without explicit challenge handling.

Fix

Add explicit .performDefaultHandling to SessionDelegate:

func urlSession(
_ session:URLSession,
didReceive challenge:URLAuthenticationChallenge,
completionHandler:@escaping(URLSession.AuthChallengeDisposition,URLCredential?)->Void){completionHandler(.performDefaultHandling,nil)}

This explicitly delegates to the system's default trust evaluation, which correctly respects user-installed CA certificates. This has no effect on normal (non-proxy) connections — it simply makes the default behavior explicit rather than implicit.

@liefran-sim
liefran-sim requested a review from Recouse as a code ownerMay 11, 2026 04:11
Without implementing urlSession(_:didReceive challenge:), URLSession
may silently reject server certificates in certain proxy/MITM scenarios
(e.g., mitmproxy, Charles Proxy) even when the CA certificate is
installed and trusted at the OS level.
Adding explicit .performDefaultHandling ensures the system's default
trust evaluation is used, which correctly respects user-installed CA
certificates. This has no effect on normal (non-proxy) connections.
@liefran-sim
liefran-simforce-pushed the fix/add-default-auth-challenge-handling branch from f962b84 to 47b2713CompareMay 11, 2026 04:42

@RecouseRecouse left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi,
Thanks for the PR!

I’ll accept it, but in the future, it would be good to support custom authentication, similar to the approach used in #47.

@Recouse
Recouse merged commit dcdd880 into Recouse:mainMay 14, 2026
3 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SSE connections fail silently through MITM proxies (missing auth challenge delegate)

2 participants

@liefran-sim@Recouse