public final class RedirectPolicyInterceptor
extends java.lang.Object
implements okhttp3.Interceptor
followRedirects cannot express:
a same-host redirect keeps the caller's headers (same origin, nothing leaks); a cross-host
redirect is still followed, but the caller's headers are stripped first, which is exactly what
makes a presigned-URL redirect from a private Nexus/Artifactory/S3-backed host work, since the
new URL carries its own authorization; an https-to-http redirect is never followed at all, so a
header can never be forwarded to the target in cleartext by way of a downgrade.OkHttpClient this is installed on to have followRedirects(false) set, so OkHttp's own redirect-following interceptor never intercepts a
3xx before this one gets to decide; this class does its own following by re-invoking Interceptor.Chain#proceed, the documented pattern for custom redirect handling.| Constructor and Description |
|---|
RedirectPolicyInterceptor() |
| Modifier and Type | Method and Description |
|---|---|
okhttp3.Response |
intercept(okhttp3.Interceptor.Chain chain) |
static boolean |
isCrossHost(okhttp3.HttpUrl from,
okhttp3.HttpUrl to) |
static boolean |
isHttpsToHttpDowngrade(okhttp3.HttpUrl from,
okhttp3.HttpUrl to) |
static boolean |
isRedirect(okhttp3.Response response) |
public okhttp3.Response intercept(okhttp3.Interceptor.Chain chain)
throws java.io.IOException
intercept in interface okhttp3.Interceptorjava.io.IOExceptionpublic static boolean isRedirect(okhttp3.Response response)
response - the response to inspect.response is a redirect status carrying a Location header.public static boolean isHttpsToHttpDowngrade(okhttp3.HttpUrl from,
okhttp3.HttpUrl to)
from - the URL being redirected from.to - the URL being redirected to.from to to would downgrade https to http.public static boolean isCrossHost(okhttp3.HttpUrl from,
okhttp3.HttpUrl to)
from - the URL being redirected from.to - the URL being redirected to.to has a different host (case-insensitively) or a different port
than from. A different port on the same hostname is still a different origin: the
caller's headers must not survive a redirect to another port any more than to another host.