ScienceDiscovery
中文 GitHub

Network Proxy Mechanism

ScienceDiscovery provides an instance-level proxy registry and unified policy model. Configuration steps are in Configure the network proxy; API fields are in REST API.

Configuration model

Type Behavior Use
custom_url Encrypted HTTP, HTTPS, or SOCKS5 URL Fixed enterprise address or credential URL
environment Reads uppercase/lowercase HTTP(S)/ALL proxy and NO_PROXY variables Container, systemd, or launcher injection
system Reads manual GNOME gsettings HTTP/HTTPS proxy Configured Linux workstation

Module policies are inherit (LLM/Web/default MCP behavior), none (explicit direct access ignoring proxy environment), or proxy:<id>. The global default is only none or proxy:<id> to avoid recursive inheritance. A referenced proxy cannot be deleted until global/model/Web/MCP references change.

Outbound integration

The Node control plane owns registry, policy, and ciphertext. SessionStore.resolveProxy(policy) yields storage-independent direct, environment, or {mode:"url",url}. Node fetch paths use proxyDispatcher(resolved,targetUrl) with protocol and NO_PROXY handling; subprocesses use proxyEnvOverlay. Logs may record mode/use but never the full URL.

New outbound code should accept ProxyPolicy, resolve closest to the request, and use the shared dispatch/environment helpers. The bundled Python MCP servers receive an already resolved environment overlay from Node and never read Node storage.

Migration, security, and limitations