diff --git a/internal/ai/ai.go b/internal/ai/ai.go index 574f35c8..5f87c926 100644 --- a/internal/ai/ai.go +++ b/internal/ai/ai.go @@ -50,7 +50,7 @@ type Manager struct { snippetGenMu sync.Mutex snippetGen map[int]uint64 dialControl ssrf.Control - toolClient *http.Client + httpClient *http.Client } // Opts contains options for initializing the Manager. @@ -111,7 +111,7 @@ func New(opts Opts) (*Manager, error) { index: newEmbeddingIndex(), snippetGen: make(map[int]uint64), dialControl: opts.DialControl, - toolClient: &http.Client{ + httpClient: &http.Client{ Timeout: 20 * time.Second, Transport: &http.Transport{ DialContext: (&net.Dialer{ diff --git a/internal/ai/tools.go b/internal/ai/tools.go index 6df5d8a7..5d8e21f6 100644 --- a/internal/ai/tools.go +++ b/internal/ai/tools.go @@ -247,7 +247,7 @@ func (m *Manager) buildToolRegistry(tctx ToolContext, allowedToolIDs []int, incl m.lo.Warn("skipping custom tool that collides with a built-in tool", "name", ct.Name) continue } - ht := newHTTPTool(ct, m.encryptionKey, m.lo, m.toolClient, tctx) + ht := newHTTPTool(ct, m.encryptionKey, m.lo, m.httpClient, tctx) registry[ht.Name()] = ht defs = append(defs, toolDef(ht)) } diff --git a/internal/ai/urlimport.go b/internal/ai/urlimport.go index c56fb454..02c81fe3 100644 --- a/internal/ai/urlimport.go +++ b/internal/ai/urlimport.go @@ -56,7 +56,7 @@ func (m *Manager) fetchURL(ctx context.Context, pageURL string) (string, string, return "", "", err } req.Header.Set("User-Agent", "libredesk") - resp, err := http.DefaultClient.Do(req) + resp, err := m.httpClient.Do(req) if err != nil { return "", "", err } diff --git a/internal/auth/auth.go b/internal/auth/auth.go index c42f4fd5..24a89d60 100644 --- a/internal/auth/auth.go +++ b/internal/auth/auth.go @@ -137,11 +137,13 @@ func newOIDCClient(dialControl ssrf.Control) *http.Client { return &http.Client{ Timeout: 10 * time.Second, Transport: &http.Transport{ + Proxy: http.ProxyFromEnvironment, DialContext: (&net.Dialer{ Timeout: 3 * time.Second, KeepAlive: 30 * time.Second, Control: dialControl, }).DialContext, + ForceAttemptHTTP2: true, TLSHandshakeTimeout: 5 * time.Second, ResponseHeaderTimeout: 5 * time.Second, },