Skip to content

Releases: grakz/proxy_settings

Release list

v1.0.2

Choose a tag to compare

@grakz grakz released this 02 May 11:07
7bd1166

proxy_settings v1.0.2

Polishes the --mitm workflow so a single configure_proxy invocation reliably ends in a coherent state, and updates the release pipeline.

Downloads

  • proxy_settings-windows-x64.exe — Intel / AMD machines.
  • proxy_settings-windows-arm64.exe — Windows on ARM (Surface Pro X, Snapdragon-X laptops, etc.).

Bug fixes

  • MITM CA is now generated before the daemon starts. Previously the daemon generated its own CA after binding its port, opening a small race where the bundle write that followed could miss the file. The parent process now pre-generates the CA so the daemon just loads an existing file.
  • A CA bundle is now written when --mitm is in use even if no corporate inspection cert is detected. Previously this silently produced a half-broken state — the MITM CA was generated but never landed in any trust bundle, so Git/npm/Node had no way to trust the local interception.
  • Removed a misleading "MITM CA not in Node bundle" warning from the daemon startup log. The daemon process inherited its environment before setx could update NODE_EXTRA_CA_CERTS, so the warning always fired on first run regardless of whether the parent was about to fix exactly that. The same diagnostic is still available on demand via auth_proxy.py --mitm-check, where the surrounding shell env makes the result meaningful.
  • Clearer error when --mitm is requested without cryptography installed (source installs only — the .exe bundles it). Exits with a one-line install hint instead of a partial setup.

CI / build

  • Build script honors the Python version actions/setup-python requested. The interpreter-detection loop preferred the Windows py launcher, which always picks the latest installed Python on the system; on the ARM64 runner that landed on 3.14.4 even though the workflow asked for 3.13. Cryptography doesn't yet ship a 3.14 Windows ARM64 wheel, so the ARM64 build fell back to compiling OpenSSL via Rust and failed. The script now searches python → python3 → py, so the version setup-python puts at the head of PATH wins.
  • Release workflow updated to Node.js 24-compatible action versions (actions/checkout@v5, actions/setup-python@v6, actions/upload-artifact@v5) and sets FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true to cover any action that hasn't shipped a Node 24 release yet. Silences the deprecation warnings.

What's Changed

  • Claude/review repo structure wxh dx by @grakz in #7
  • Claude/review repo structure wxh dx by @grakz in #8

Full Changelog: v1.0.1...v1.0.2

What's Changed

  • Claude/review repo structure wxh dx by @grakz in #7
  • Claude/review repo structure wxh dx by @grakz in #8

Full Changelog: v1.0.1...v1.0.2

v1.0.0

Choose a tag to compare

@github-actions github-actions released this 02 May 09:56
2d138d8

proxy_settings v1.0.0

First public release. A toolkit that makes command-line developer tools (Git, npm, pip, Node.js, and anything that honors HTTPS_PROXY) work on Windows behind a corporate proxy.

Download

  • proxy_settings.exe — standalone Windows x64 binary attached to this release. No Python install required. See Quick start → Option A in the README.
  • From source — pip install pywin32 cryptography certifi && python configure_proxy.py.

What's included

Automatic proxy discovery. Walks env vars → Windows registry static proxy → registry AutoConfigURL → DNS WPAD → PAC file (evaluated with Node.js when present, with a built-in Python evaluator covering shExpMatch / dnsDomainIs / isInNet / isPlainHostName / dnsResolve / myIpAddress / isResolvable / dnsDomainLevels as a fallback).

Corporate TLS-inspection CA discovery. Diffs the Windows ROOT store against certifi, scores candidates by name (Zscaler, BlueCoat, Netskope, Forcepoint, Palo Alto, McAfee, …) and recency, and confirms the active inspection CA via AKI/SKI matching against a TLS probe. Falls back to a probe-based capture path (Python ≥ 3.13's get_unverified_chain, openssl s_client -proxy, leaf-only) if the store diff turns up nothing. Manual --ca-import always wins.

Combined CA bundle. Writes certifi + corporate root(s) + the local MITM CA to ~/.config/configure_proxy/ca-bundle.pem and points Git (http.sslCAInfo), npm (cafile), pip ([global] cert), and Node (NODE_EXTRA_CA_CERTS) at it.

Local NTLM/Negotiate auth proxy. auth_proxy.py listens on 127.0.0.1:3128, accepts unauthenticated requests from local tools, and authenticates upstream against the corporate proxy using Windows SSPI — i.e. your logged-in credentials, no password storage. Handles the full three-round CONNECT handshake on a single TCP connection.

McAfee Web Gateway "progress page" workaround (--mitm). When MWG replaces large downloads (npm tarballs, Prisma binaries, etc.) with HTML "Please Wait" / "Click here to get the file" pages, --mitm <hosts> terminates TLS locally with a leaf cert signed by an auto-generated local CA, drives the WAITING → POLL → READY state machine on the user's behalf, follows the &dl link, and serves the real file bytes back to the client. Includes a Content-Length/Transfer-Encoding rewrite to keep pnpm/undici from RST-ing on de-chunked responses.

Persistence. Every successful run saves its flags to ~/.config/configure_proxy/config.json so subsequent invocations (e.g. after a reboot) are a no-arg proxy_settings.exe.

Standalone Windows binary. PyInstaller --onefile + UPX, built reproducibly on windows-latest via the included Actions workflow. Bundles the Python interpreter, pywin32, cryptography, certifi, and all three project scripts. A single binary doubles as both the configurator and the auth daemon via an internal sentinel-arg dispatcher.

Quick start

:: Option A — prebuilt binary
proxy_settings.exe

:: Option B — from source
pip install pywin32 cryptography certifi
python configure_proxy.py