{"version":"2.1.284","anchor":"sandbox-tls-terminate-proxy-reuses-upstream-connections-and","canonical_anchor":"sandbox-tls-terminate-proxy-reuses-upstream-connections-and","heading":"Sandbox HTTPS proxy reuses connections and sends the right Host header for custom ports","tier":"notice","area":"Sandbox","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284\/e\/sandbox-tls-terminate-proxy-reuses-upstream-connections-and","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284","markdown":"### Sandbox HTTPS proxy reuses connections and sends the right Host header for custom ports\n\nThe sandbox's HTTPS proxy now keeps connections open for reuse and includes a non-default port in the Host header it forwards\n\n**What**\n\nWhen the sandbox limits network access, some HTTPS traffic from commands passes through a proxy, a go-between that opens the encrypted connection and forwards the request. That proxy's behaviour has changed in several ways:\n\n- Connections to a website are now kept open and reused, one connection at a time, instead of opening a new one for every request.\n\n- The website's looked-up address is remembered, and forgotten again after an error.\n\n- The `Host` header, which tells the website which name was asked for, is now rebuilt with the port number when the port is not the standard one. Before, the header was removed.\n\n- If a reused connection is cut off by the website, the proxy now closes the command's connection instead of answering with a 502 Bad Gateway error.\n\n- A request refused by the allow list now gets the same refusal response as other blocked connections, with the message \"Connection blocked by network allowlist\".\n\n**Why**\n\nWebsites on a non-standard port could receive the wrong `Host` header through the sandbox, which this fixes. Reusing connections also means fewer secure handshakes, so repeated requests to the same site do less work.\n\n- Area: Sandbox\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 1\/5"}