I would like to revive this issue, as it just bit me.
A vendor provider a download URL of the form ftp: // username : password @ hostname/path/filename. (Spaces added to prevent this from becoming a hyperlink.)
Both Standard Mode and Transparent Mode proxies seem to strip the credentials.
Log files were nearly useless, because web filter reported everything as passed, until I noticed that the logged URL had the credentials were stripped.
Eventually, I was able to download the file using an FTP client.
I have some other downloads that are failing, and I am having a hard time understanding why, because they are managed by product-specific software update managers, and my logs (web, ftp, firewall) have not been unhelpful.
Would it have been possible to make this work in a browser?
Does anyone have any advice for detecting when a problem of this sort is occurring?