fix(esp_http_client): require https->https for cross-scheme redirects

esp_http_client_set_redirection() now rejects any redirect target whose
scheme is not https:// when the origin is HTTPS. This catches http, ftp,
ws and any other scheme before client state is mutated. Same-host /
https-to-https redirects are unaffected. Apps that intentionally want
mixed-scheme redirects can set disable_auto_redirect=true and handle
HTTP_EVENT_REDIRECT.
This commit is contained in:
Aditya Patwardhan
2026-05-27 19:58:17 +05:30
parent 8d2cce01da
commit d720b5562d
3 changed files with 22 additions and 3 deletions
@@ -682,6 +682,10 @@ static const esp_err_msg_t esp_err_msg_table[] = {
# ifdef ESP_ERR_HTTP_INCOMPLETE_DATA
ERR_TBL_IT(ESP_ERR_HTTP_INCOMPLETE_DATA), /* 28684 0x700c Incomplete data received, less than
Content-Length or last chunk */
# endif
# ifdef ESP_ERR_HTTP_REDIRECT_DOWNGRADE
ERR_TBL_IT(ESP_ERR_HTTP_REDIRECT_DOWNGRADE), /* 28685 0x700d HTTPS origin redirected to a non-HTTPS
scheme (downgrade blocked) */
# endif
// components/esp-tls/esp_tls_errors.h
# ifdef ESP_ERR_ESP_TLS_BASE