Class RedirectPolicyInterceptor

java.lang.Object
io.github.intisy.gradle.github.impl.download.RedirectPolicyInterceptor
All Implemented Interfaces:
okhttp3.Interceptor

public final class RedirectPolicyInterceptor extends Object implements okhttp3.Interceptor
Follows a redirect with a policy OkHttp's own on/off followRedirects cannot express: a same-host redirect keeps the caller's headers (same origin, nothing leaks); a cross-host redirect is still followed, but the caller's headers are stripped first, which is exactly what makes a presigned-URL redirect from a private Nexus/Artifactory/S3-backed host work, since the new URL carries its own authorization; an https-to-http redirect is never followed at all, so a header can never be forwarded to the target in cleartext by way of a downgrade.
Implementation Note:
Requires the OkHttpClient this is installed on to have followRedirects(false) set, so OkHttp's own redirect-following interceptor never intercepts a 3xx before this one gets to decide; this class does its own following by re-invoking Interceptor.Chain.proceed(okhttp3.Request), the documented pattern for custom redirect handling.
  • Nested Class Summary

    Nested classes/interfaces inherited from interface okhttp3.Interceptor

    okhttp3.Interceptor.Chain, okhttp3.Interceptor.Companion
  • Field Summary

    Fields inherited from interface okhttp3.Interceptor

    Companion
  • Constructor Summary

    Constructors
    Constructor
    Description
     
  • Method Summary

    Modifier and Type
    Method
    Description
    okhttp3.Response
    intercept(okhttp3.Interceptor.Chain chain)
     
    static boolean
    isCrossHost(okhttp3.HttpUrl from, okhttp3.HttpUrl to)
     
    static boolean
    isHttpsToHttpDowngrade(okhttp3.HttpUrl from, okhttp3.HttpUrl to)
     
    static boolean
    isRedirect(okhttp3.Response response)
     

    Methods inherited from class java.lang.Object

    clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait
  • Constructor Details

    • RedirectPolicyInterceptor

      public RedirectPolicyInterceptor()
  • Method Details

    • intercept

      public okhttp3.Response intercept(okhttp3.Interceptor.Chain chain) throws IOException
      Specified by:
      intercept in interface okhttp3.Interceptor
      Throws:
      IOException
    • isRedirect

      public static boolean isRedirect(okhttp3.Response response)
      Parameters:
      response - the response to inspect.
      Returns:
      true if response is a redirect status carrying a Location header.
    • isHttpsToHttpDowngrade

      public static boolean isHttpsToHttpDowngrade(okhttp3.HttpUrl from, okhttp3.HttpUrl to)
      Parameters:
      from - the URL being redirected from.
      to - the URL being redirected to.
      Returns:
      true if following the redirect from from to to would downgrade https to http.
    • isCrossHost

      public static boolean isCrossHost(okhttp3.HttpUrl from, okhttp3.HttpUrl to)
      Parameters:
      from - the URL being redirected from.
      to - the URL being redirected to.
      Returns:
      true if to has a different host (case-insensitively) or a different port than from. A different port on the same hostname is still a different origin: the caller's headers must not survive a redirect to another port any more than to another host.