Skip to content

Commit f77202a

Browse files
committed
Apply WinHTTP root checks only to HTTPS
Plain HTTP requests have no server certificate to validate. Avoid rejecting local and non-TLS endpoints when the Microsoft-root policy is enabled for an HTTPS configuration. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: aefd8d4a-8755-4853-8e6b-267cce60e3a9
1 parent c0f5967 commit f77202a

1 file changed

Lines changed: 4 additions & 3 deletions

File tree

‎lib/http/HttpClient_WinHttp.cpp‎

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -48,6 +48,7 @@ class WinHttpRequestWrapper : public std::enable_shared_from_this<WinHttpRequest
4848
std::vector<uint8_t> m_readBuffer;
4949
std::atomic<bool> isCallbackCalled {false};
5050
bool isAborted {false};
51+
bool m_isHttps {false};
5152
WinHttpCallbackContext* m_callbackContext {nullptr};
5253

5354
public:
@@ -280,11 +281,11 @@ class WinHttpRequestWrapper : public std::enable_shared_from_this<WinHttpRequest
280281
}
281282

282283
std::wstring wMethod = to_utf16_string(m_request->m_method);
283-
bool isHttps = (urlc.nScheme == INTERNET_SCHEME_HTTPS);
284+
m_isHttps = (urlc.nScheme == INTERNET_SCHEME_HTTPS);
284285
m_hRequest = ::WinHttpOpenRequest(
285286
m_hConnect, wMethod.c_str(), path, NULL, WINHTTP_NO_REFERER,
286287
WINHTTP_DEFAULT_ACCEPT_TYPES,
287-
WINHTTP_FLAG_REFRESH | (isHttps ? WINHTTP_FLAG_SECURE : 0));
288+
WINHTTP_FLAG_REFRESH | (m_isHttps ? WINHTTP_FLAG_SECURE : 0));
288289
if (m_hRequest == nullptr)
289290
{
290291
DWORD dwError = ::GetLastError();
@@ -435,7 +436,7 @@ class WinHttpRequestWrapper : public std::enable_shared_from_this<WinHttpRequest
435436
// TLS negotiation and response-header receipt are both complete here,
436437
// so WINHTTP_OPTION_SERVER_CERT_CONTEXT is available for the
437438
// configured Microsoft-root enforcement.
438-
if (self->m_parent.IsMsRootCheckRequired() && !self->isMsRootCert(request))
439+
if (self->m_isHttps && self->m_parent.IsMsRootCheckRequired() && !self->isMsRootCert(request))
439440
{
440441
self->onRequestComplete(ERROR_WINHTTP_SECURE_INVALID_CERT);
441442
return;

0 commit comments

Comments
 (0)