When your client talks to an HTTPS site through an HTTP proxy, it cannot hand the proxy the request itself: the request is encrypted end to end. So it first asks the proxy for a tunnel:
CONNECT example.com:443 HTTP/1.1
Host: example.com:443
Proxy-Authorization: Basic dXNlcjpwYXNz
If the proxy accepts, it answers HTTP/1.1 200 Connection established and from then on copies bytes in both directions without reading them. Your client runs the TLS handshake with the website through that tunnel, so the proxy sees the hostname and port you asked for and how many bytes moved, but not the pages, headers or cookies inside.
Why it matters when something breaks
The position of an error tells you who sent it. An error in reply to the CONNECT line, such as 407 Proxy Authentication Required, comes from the proxy. An error after Connection established comes from the website. Run the request with curl -v and look for the CONNECT line to see which side you are dealing with; the proxy error codes guide walks through each case.
CONNECT and credentials
Proxy credentials travel in the Proxy-Authorization header of the CONNECT request, base64-encoded rather than encrypted. They reach the proxy and stop there; the website never sees them. See proxy authentication for when an IP allowlist is the better choice.