|
1 | 1 | import { createServer, type Server, type IncomingMessage } from "node:http"; |
| 2 | +import { createServer as createHTTPSServer } from "node:https"; |
| 3 | +import { readFileSync } from "node:fs"; |
| 4 | +import { join } from "node:path"; |
2 | 5 | import { Duplex } from "node:stream"; |
3 | 6 | import { connect, type AddressInfo } from "node:net"; |
4 | 7 | import { afterAll, beforeAll, describe, expect, it } from "vitest"; |
@@ -683,4 +686,170 @@ describe("proxyUpgrade", () => { |
683 | 686 | proxy.close(); |
684 | 687 | }); |
685 | 688 | }); |
| 689 | + |
| 690 | + describe("wss:// (TLS upstream)", () => { |
| 691 | + const __dirname = new URL(".", import.meta.url).pathname; |
| 692 | + const sslOpts = { |
| 693 | + key: readFileSync(join(__dirname, "fixtures", "agent2-key.pem")), |
| 694 | + cert: readFileSync(join(__dirname, "fixtures", "agent2-cert.pem")), |
| 695 | + }; |
| 696 | + |
| 697 | + it("should use HTTPS request for wss:// addr", async () => { |
| 698 | + // Create an HTTPS server with WebSocket support |
| 699 | + const httpsServer = createHTTPSServer(sslOpts); |
| 700 | + const targetWs = new ws.WebSocketServer({ server: httpsServer }); |
| 701 | + |
| 702 | + targetWs.on("connection", (socket) => { |
| 703 | + socket.on("message", (msg) => { |
| 704 | + socket.send("secure-echo:" + msg.toString("utf8")); |
| 705 | + }); |
| 706 | + }); |
| 707 | + |
| 708 | + await new Promise<void>((resolve) => { |
| 709 | + httpsServer.listen(0, "127.0.0.1", resolve); |
| 710 | + }); |
| 711 | + const targetPort = (httpsServer.address() as AddressInfo).port; |
| 712 | + |
| 713 | + const proxy = createProxyServer(`wss://127.0.0.1:${targetPort}`, { |
| 714 | + secure: false, |
| 715 | + }); |
| 716 | + const proxyPort = await listenServer(proxy); |
| 717 | + |
| 718 | + const { promise, resolve } = Promise.withResolvers<void>(); |
| 719 | + const client = new ws.WebSocket("ws://127.0.0.1:" + proxyPort); |
| 720 | + |
| 721 | + client.on("open", () => { |
| 722 | + client.send("tls-test"); |
| 723 | + }); |
| 724 | + |
| 725 | + client.on("message", (msg) => { |
| 726 | + expect(msg.toString("utf8")).toBe("secure-echo:tls-test"); |
| 727 | + client.close(); |
| 728 | + targetWs.close(); |
| 729 | + httpsServer.close(); |
| 730 | + proxy.close(() => resolve()); |
| 731 | + }); |
| 732 | + |
| 733 | + client.on("error", (err) => { |
| 734 | + targetWs.close(); |
| 735 | + httpsServer.close(); |
| 736 | + proxy.close(); |
| 737 | + throw err; |
| 738 | + }); |
| 739 | + |
| 740 | + await promise; |
| 741 | + }); |
| 742 | + |
| 743 | + it("should use HTTPS request for https:// addr", async () => { |
| 744 | + const httpsServer = createHTTPSServer(sslOpts); |
| 745 | + const targetWs = new ws.WebSocketServer({ server: httpsServer }); |
| 746 | + |
| 747 | + targetWs.on("connection", (socket) => { |
| 748 | + socket.on("message", (msg) => { |
| 749 | + socket.send("https-echo:" + msg.toString("utf8")); |
| 750 | + }); |
| 751 | + }); |
| 752 | + |
| 753 | + await new Promise<void>((resolve) => { |
| 754 | + httpsServer.listen(0, "127.0.0.1", resolve); |
| 755 | + }); |
| 756 | + const targetPort = (httpsServer.address() as AddressInfo).port; |
| 757 | + |
| 758 | + const proxy = createProxyServer(`https://127.0.0.1:${targetPort}`, { |
| 759 | + secure: false, |
| 760 | + }); |
| 761 | + const proxyPort = await listenServer(proxy); |
| 762 | + |
| 763 | + const { promise, resolve } = Promise.withResolvers<void>(); |
| 764 | + const client = new ws.WebSocket("ws://127.0.0.1:" + proxyPort); |
| 765 | + |
| 766 | + client.on("open", () => { |
| 767 | + client.send("https-test"); |
| 768 | + }); |
| 769 | + |
| 770 | + client.on("message", (msg) => { |
| 771 | + expect(msg.toString("utf8")).toBe("https-echo:https-test"); |
| 772 | + client.close(); |
| 773 | + targetWs.close(); |
| 774 | + httpsServer.close(); |
| 775 | + proxy.close(() => resolve()); |
| 776 | + }); |
| 777 | + |
| 778 | + client.on("error", (err) => { |
| 779 | + targetWs.close(); |
| 780 | + httpsServer.close(); |
| 781 | + proxy.close(); |
| 782 | + throw err; |
| 783 | + }); |
| 784 | + |
| 785 | + await promise; |
| 786 | + }); |
| 787 | + |
| 788 | + it("should use plain HTTP request for ws:// addr (no TLS)", async () => { |
| 789 | + // Verify ws:// still uses plain HTTP (not HTTPS) |
| 790 | + const proxy = createProxyServer({ host: "127.0.0.1", port: wsPort }); |
| 791 | + const proxyPort = await listenServer(proxy); |
| 792 | + |
| 793 | + const { promise, resolve } = Promise.withResolvers<void>(); |
| 794 | + const client = new ws.WebSocket("ws://127.0.0.1:" + proxyPort); |
| 795 | + |
| 796 | + client.on("open", () => { |
| 797 | + client.send("plain-test"); |
| 798 | + }); |
| 799 | + |
| 800 | + client.on("message", (msg) => { |
| 801 | + expect(msg.toString("utf8")).toBe("echo:plain-test"); |
| 802 | + client.close(); |
| 803 | + proxy.close(() => resolve()); |
| 804 | + }); |
| 805 | + |
| 806 | + await promise; |
| 807 | + }); |
| 808 | + }); |
| 809 | + |
| 810 | + describe("non-upgrade response with destroyed socket", () => { |
| 811 | + it("should consume response body when socket is already destroyed", async () => { |
| 812 | + // Regression: when the client socket is destroyed before the upstream |
| 813 | + // non-upgrade response arrives, the response stream must be consumed |
| 814 | + // (res.resume()) to avoid unhandled stream errors. |
| 815 | + const { promise: targetReqReceived, resolve: onTargetReq } = Promise.withResolvers<void>(); |
| 816 | + const { promise: canRespond, resolve: allowResponse } = Promise.withResolvers<void>(); |
| 817 | + |
| 818 | + const targetServer = createServer(async (_req, res) => { |
| 819 | + onTargetReq(); |
| 820 | + await canRespond; |
| 821 | + // Send a larger response body to make unconsumed stream errors more likely |
| 822 | + res.writeHead(503); |
| 823 | + res.end("Service Unavailable — " + "x".repeat(1024)); |
| 824 | + }); |
| 825 | + const targetPort = await listenServer(targetServer); |
| 826 | + |
| 827 | + const server = createServer(); |
| 828 | + const { promise, resolve } = Promise.withResolvers<void>(); |
| 829 | + |
| 830 | + server.on("upgrade", (req, socket, head) => { |
| 831 | + // Destroy socket before upstream responds |
| 832 | + targetReqReceived.then(() => { |
| 833 | + socket.destroy(); |
| 834 | + setTimeout(allowResponse, 10); |
| 835 | + }); |
| 836 | + |
| 837 | + proxyUpgrade({ host: "127.0.0.1", port: targetPort }, req, socket, head).catch(() => { |
| 838 | + // Give time for any potential unhandled stream errors to surface |
| 839 | + setTimeout(resolve, 50); |
| 840 | + }); |
| 841 | + }); |
| 842 | + |
| 843 | + const port = await listenServer(server); |
| 844 | + |
| 845 | + const sock = connect(port, "127.0.0.1", () => { |
| 846 | + sock.write(wsUpgradeRequest(port)); |
| 847 | + }); |
| 848 | + sock.on("error", () => {}); |
| 849 | + |
| 850 | + await promise; |
| 851 | + targetServer.close(); |
| 852 | + server.close(); |
| 853 | + }); |
| 854 | + }); |
686 | 855 | }); |
0 commit comments