diff --git a/src/Api.ps1 b/src/Api.ps1 index b6f7581..7884c7f 100644 --- a/src/Api.ps1 +++ b/src/Api.ps1 @@ -183,8 +183,26 @@ function Get-UpdateCheckEndpoint { if ($token) { $headers['Authorization'] = "token $token" } try { [Net.ServicePointManager]::SecurityProtocol = [Net.ServicePointManager]::SecurityProtocol -bor [Net.SecurityProtocolType]::Tls12 } catch {} + + # Proxy: Hinter authentifizierten Unternehmens-Proxys (NTLM/Kerberos) scheitert + # Invoke-RestMethod sonst mit "407 Proxyauthentifizierung erforderlich", weil + # standardmaessig keine Anmeldeinformationen an den Proxy gesendet werden. Die + # angemeldeten Windows-Credentials an den (System-)Proxy durchreichen. Optional + # laesst sich ein expliziter Proxy ueber Settings.update.proxy setzen. + $proxyArgs = @{} try { - $rel = Invoke-RestMethod -Uri $api -Headers $headers -Method GET -TimeoutSec 8 + $proxyUrl = '' + if ($script:Settings.update -and $script:Settings.update.proxy) { $proxyUrl = [string]$script:Settings.update.proxy } + if ($proxyUrl) { + $proxyArgs['Proxy'] = $proxyUrl + $proxyArgs['ProxyUseDefaultCredentials'] = $true + } elseif ([System.Net.WebRequest]::DefaultWebProxy) { + [System.Net.WebRequest]::DefaultWebProxy.Credentials = [System.Net.CredentialCache]::DefaultCredentials + } + } catch {} + + try { + $rel = Invoke-RestMethod -Uri $api -Headers $headers -Method GET -TimeoutSec 8 @proxyArgs $latest = ([string]$rel.tag_name).TrimStart('v','V') $out.latest = $latest $out.releaseUrl = [string]$rel.html_url