[roll] Roll fuchsia [http-client] Prevent insecure redirect downgrade

This change implements protection against insecure redirect downgrades in
`http-client`. When a client requests a resource via HTTPS, the client
should not be downgraded to HTTP via a redirect, as this exposes the
connection to MITM attacks.

Modify `calculate_redirect` to detect if the transition is from
`https` to `http` (case-insensitive) and block the redirect by returning
`None`. Additionally, when `None` is returned, set `redirect: None`
instead of `RedirectTarget: None`.

Add tests for redirect calculations.

Original-Original-Bug: 517279167
Test: fx test http-client-test

Original-Original-Reviewed-on: https://fuchsia-review.googlesource.com/c/fuchsia/+/1637135
Original-Original-Revision: 24a789e3e2d7d9a02288860393287ad6f33fa769
GitOrigin-RevId: a3adfe44cb1761d53e139f3db6bf9a035bf31937
Change-Id: I82dad5c184b01c99d77e04afe4a0f8d8591a9169
Reviewed-on: https://fuchsia-review.googlesource.com/c/integration/+/1649242
Cr-Commit-Position: refs/heads/main@{#194558}
1 file changed
tree: f3c64f5a34838dd10bd7feb1ad667be8d9179258
  1. ctf/
  2. git-hooks/
  3. infra/
  4. third_party/
  5. cobalt
  6. flower
  7. jiri.lock
  8. MILESTONE
  9. minimal
  10. prebuilts
  11. README.md
  12. stem
  13. test_durations
README.md

Integration

This repository contains Fuchsia's Global Integration manifest files.

Making changes

All changes should be made to the internal version of this repository. Our infrastructure automatically updates this version when the internal one changes.

Currently all changes must be made by a Google employee. Non-Google employees wishing to make a change can ask for assistance in one of the communication channels documented at get involved.

Obtaining the source

First install Jiri.

Next run:

$ jiri init
$ jiri import minimal https://fuchsia.googlesource.com/integration
$ jiri update

Third party

Third party projects should have their own subdirectory in ./third_party.