From de32f6201c50d86c490a927fcc2d1682b5b22941 Mon Sep 17 00:00:00 2001 From: Marco Wende Date: Mon, 14 Sep 2026 10:59:02 +0200 Subject: [PATCH] =?UTF-8?q?Update-Check:=20Proxy-Authentifizierung=20unter?= =?UTF-8?q?st=C3=BCtzen?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Hinter authentifizierten Unternehmens-Proxys (NTLM/Kerberos) scheiterte der Update-Check mit HTTP 407, weil Invoke-RestMethod keine Anmeldeinformationen an den Proxy sendet. Jetzt werden die angemeldeten Windows-Credentials an den System-Proxy durchgereicht; optionaler expliziter Proxy via settings.json -> update.proxy. Co-Authored-By: Claude Opus 4.8 --- src/Api.ps1 | 20 +++++++++++++++++++- 1 file changed, 19 insertions(+), 1 deletion(-) diff --git a/src/Api.ps1 b/src/Api.ps1 index b6f7581..7884c7f 100644 --- a/src/Api.ps1 +++ b/src/Api.ps1 @@ -183,8 +183,26 @@ function Get-UpdateCheckEndpoint { if ($token) { $headers['Authorization'] = "token $token" } try { [Net.ServicePointManager]::SecurityProtocol = [Net.ServicePointManager]::SecurityProtocol -bor [Net.SecurityProtocolType]::Tls12 } catch {} + + # Proxy: Hinter authentifizierten Unternehmens-Proxys (NTLM/Kerberos) scheitert + # Invoke-RestMethod sonst mit "407 Proxyauthentifizierung erforderlich", weil + # standardmaessig keine Anmeldeinformationen an den Proxy gesendet werden. Die + # angemeldeten Windows-Credentials an den (System-)Proxy durchreichen. Optional + # laesst sich ein expliziter Proxy ueber Settings.update.proxy setzen. + $proxyArgs = @{} try { - $rel = Invoke-RestMethod -Uri $api -Headers $headers -Method GET -TimeoutSec 8 + $proxyUrl = '' + if ($script:Settings.update -and $script:Settings.update.proxy) { $proxyUrl = [string]$script:Settings.update.proxy } + if ($proxyUrl) { + $proxyArgs['Proxy'] = $proxyUrl + $proxyArgs['ProxyUseDefaultCredentials'] = $true + } elseif ([System.Net.WebRequest]::DefaultWebProxy) { + [System.Net.WebRequest]::DefaultWebProxy.Credentials = [System.Net.CredentialCache]::DefaultCredentials + } + } catch {} + + try { + $rel = Invoke-RestMethod -Uri $api -Headers $headers -Method GET -TimeoutSec 8 @proxyArgs $latest = ([string]$rel.tag_name).TrimStart('v','V') $out.latest = $latest $out.releaseUrl = [string]$rel.html_url