Skip to content

v1.0.0

Choose a tag to compare

@github-actions github-actions released this 02 May 09:56
· 22 commits to main since this release
2d138d8

proxy_settings v1.0.0

First public release. A toolkit that makes command-line developer tools (Git, npm, pip, Node.js, and anything that honors HTTPS_PROXY) work on Windows behind a corporate proxy.

Download

  • proxy_settings.exe — standalone Windows x64 binary attached to this release. No Python install required. See Quick start → Option A in the README.
  • From source — pip install pywin32 cryptography certifi && python configure_proxy.py.

What's included

Automatic proxy discovery. Walks env vars → Windows registry static proxy → registry AutoConfigURL → DNS WPAD → PAC file (evaluated with Node.js when present, with a built-in Python evaluator covering shExpMatch / dnsDomainIs / isInNet / isPlainHostName / dnsResolve / myIpAddress / isResolvable / dnsDomainLevels as a fallback).

Corporate TLS-inspection CA discovery. Diffs the Windows ROOT store against certifi, scores candidates by name (Zscaler, BlueCoat, Netskope, Forcepoint, Palo Alto, McAfee, …) and recency, and confirms the active inspection CA via AKI/SKI matching against a TLS probe. Falls back to a probe-based capture path (Python ≥ 3.13's get_unverified_chain, openssl s_client -proxy, leaf-only) if the store diff turns up nothing. Manual --ca-import always wins.

Combined CA bundle. Writes certifi + corporate root(s) + the local MITM CA to ~/.config/configure_proxy/ca-bundle.pem and points Git (http.sslCAInfo), npm (cafile), pip ([global] cert), and Node (NODE_EXTRA_CA_CERTS) at it.

Local NTLM/Negotiate auth proxy. auth_proxy.py listens on 127.0.0.1:3128, accepts unauthenticated requests from local tools, and authenticates upstream against the corporate proxy using Windows SSPI — i.e. your logged-in credentials, no password storage. Handles the full three-round CONNECT handshake on a single TCP connection.

McAfee Web Gateway "progress page" workaround (--mitm). When MWG replaces large downloads (npm tarballs, Prisma binaries, etc.) with HTML "Please Wait" / "Click here to get the file" pages, --mitm <hosts> terminates TLS locally with a leaf cert signed by an auto-generated local CA, drives the WAITING → POLL → READY state machine on the user's behalf, follows the &dl link, and serves the real file bytes back to the client. Includes a Content-Length/Transfer-Encoding rewrite to keep pnpm/undici from RST-ing on de-chunked responses.

Persistence. Every successful run saves its flags to ~/.config/configure_proxy/config.json so subsequent invocations (e.g. after a reboot) are a no-arg proxy_settings.exe.

Standalone Windows binary. PyInstaller --onefile + UPX, built reproducibly on windows-latest via the included Actions workflow. Bundles the Python interpreter, pywin32, cryptography, certifi, and all three project scripts. A single binary doubles as both the configurator and the auth daemon via an internal sentinel-arg dispatcher.

Quick start

:: Option A — prebuilt binary
proxy_settings.exe

:: Option B — from source
pip install pywin32 cryptography certifi
python configure_proxy.py