security

Why BareProxy Routes on the Same Path It Forwards

Many proxy bypasses share one cause: the proxy reads a path one way and the application reads it another. A rule that blocks /admin/ does nothing if the request arrives as /api/%2e%2e/admin and the application decodes it after the proxy has let it through.

BareProxy normalizes every path once. It decodes escapes of plain characters, resolves . and .. segments, and merges runs of slashes. Then it routes on that form and sends the backend exactly the same form. Encoded slashes and backslashes are refused unless a site opts in.

One path in, one path out: how BareProxy normalizes paths before routing and forwarding

The same idea covers request framing. BareProxy never passes a client’s framing bytes to a backend. Go’s HTTP server parses the request, and BareProxy writes a fresh one with its own framing. Request smuggling needs the proxy and the backend to read the same bytes in two ways, and here they never read the same bytes.

The platform page lists the rest of BareProxy’s design rules.