{"version":"2.1.280","anchor":"proxy-auth-helper-retry-detection-widened-to-tunnelconnect","canonical_anchor":"proxy-auth-helper-retry-detection-widened-to-tunnelconnect","heading":"Proxy auth helper retry detection widened to tunnel\/CONNECT errors","tier":"notice","area":"Elsewhere","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.280\/e\/proxy-auth-helper-retry-detection-widened-to-tunnelconnect","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.280","markdown":"### Proxy auth helper retry detection widened to tunnel\/CONNECT errors\n\nProxy auth helper now also detects 407 errors hidden inside proxy-tunnel\/CONNECT failures\n\n**What**\n\nClaude Code's configurable proxy authentication helper (enabled via `CLAUDE_CODE_ENABLE_PROXY_AUTH_HELPER`) kicks in when a proxy responds with an HTTP 407 (authentication required) status. Previously this only checked a single, direct status field. It now uses a new helper that also recognizes 407 errors buried inside a proxy-tunnel error (`ERR_PROXY_TUNNEL`) or wrapped inside other exception types, and extracts the `proxy-authenticate` challenge header from those cases too. The retry decision now goes through an additional gating step before the auth cache is reset and the pending challenge is stored.\n\n**Why**\n\nSome proxies report authentication failures as tunnel\/CONNECT errors rather than a plain HTTP response, so this change lets the proxy auth helper catch and retry those cases too, instead of missing them and failing the connection.\n\n- Area: Elsewhere\n- Names: `CLAUDE_CODE_ENABLE_PROXY_AUTH_HELPER`\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 1\/5"}