What
When the sandbox limits network access, some HTTPS traffic from commands passes through a proxy, a go-between that opens the encrypted connection and forwards the request. That proxy's behaviour has changed in several ways:
- Connections to a website are now kept open and reused, one connection at a time, instead of opening a new one for every request.
- The website's looked-up address is remembered, and forgotten again after an error.
- The
Hostheader, which tells the website which name was asked for, is now rebuilt with the port number when the port is not the standard one. Before, the header was removed. - If a reused connection is cut off by the website, the proxy now closes the command's connection instead of answering with a 502 Bad Gateway error.
- A request refused by the allow list now gets the same refusal response as other blocked connections, with the message "Connection blocked by network allowlist".
Why
Websites on a non-standard port could receive the wrong Host header through the sandbox, which this fixes. Reusing connections also means fewer secure handshakes, so repeated requests to the same site do less work.