# CONNECT tunnel failed, response 403 lab

This download reproduces `CONNECT tunnel failed, response 403` on your own
machine. It backs the article at
https://ipvolt.com/blog/connect-tunnel-failed-403.

`lab.mjs` starts a small Node.js HTTP proxy on `127.0.0.1` that behaves like a
sandbox or CI egress allowlist: it tunnels `CONNECT` only to `example.com` on
port 443 and answers `403 Forbidden` to every other `CONNECT` and to plain-HTTP
requests for any other host. A second port demands Basic proxy authentication,
so the 407 wording can be compared across curl versions. The lab then runs
curl, Python Requests and Node.js `fetch` through the proxy and writes every
command, exit code, stdout and stderr to a JSON file.

Requirements: Node.js 24 or later, curl, Python 3 with `requests`, and network
access to `example.com` for the allowed cases. Nothing is sent to `example.org`:
the proxy refuses those requests itself.

```sh
node lab.mjs local-results.json
```

Optional environment variables:

- `PYTHON`: the Python interpreter to use (default `python3`).
- `CURLS`: comma-separated curl binaries to compare (default `curl`).

`results.json` is the run recorded on 2 October 2026 with curl 8.15.0, 8.16.0,
8.17.0, 8.18.0 and 8.22.0, Python 3.14.4 with Requests 2.34.2 and urllib3
2.8.0, and Node.js 24.20.0. Binary paths are shortened to `curl-<version>`,
`python3` and `node`; proxy ports are random per run.
