You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

通过Squid代理使用socket.io-client连接时出现502 Bad Gateway错误

通过Squid代理使用socket.io-client时遭遇502 Bad Gateway错误

客户端连接代码

var proxy = require('socket.io-proxy');
proxy.init('http://x.x.x.x:3128');
var socket = proxy.connect('https://example.com');

依赖与修改说明

使用stbrenner/socket.io-proxy作为socket.io-client的代理包装器,采用master分支(要求socket.io-client >=2.0.4),并做了两处修改:

  • 修复请求中未包含hostname导致的400错误
  • 硬编码使用HTTP连接Squid(尽管目标服务器是HTTPS),因为Squid仅监听HTTP端口但支持代理443端口

客户端错误日志

error: Node connect error Error: xhr poll error
    at XHR.Transport.onError (/srv/app/node_modules/engine.io-client/lib/transport.js:68:13)
    at Request.<anonymous> (/srv/app/node_modules/engine.io-client/lib/transports/polling-xhr.js:132:10)
    at Request.Emitter.emit (/srv/app/node_modules/engine.io-client/node_modules/component-emitter/index.js:145:20)
    at Request.onError (/srv/app/node_modules/engine.io-client/lib/transports/polling-xhr.js:314:8)
    at Timeout._onTimeout (/srv/app/node_modules/engine.io-client/lib/transports/polling-xhr.js:261:18)
    at listOnTimeout (internal/timers.js:557:17)
    at processTimers (internal/timers.js:500:7) severity=400, node_uuid=9ea851cb-e6ee-4dfd-a2cb-3fe2586532d0

Squid配置

acl localnet src 0.0.0.1-0.255.255.255  # RFC 1122 "this" network (LAN)
aclocalnet src 10.0.0.0/8             # RFC 1918 local private network (LAN)
aclocalnet src 100.64.0.0/10          # RFC 6598 shared address space (CGN)
aclocalnet src 169.254.0.0/16         # RFC 3927 link-local (directly plugged) machines
aclocalnet src 172.16.0.0/12          # RFC 1918 local private network (LAN)
aclocalnet src 192.168.0.0/16         # RFC 1918 local private network (LAN)
aclocalnet src fc00::/7               # RFC 4193 local private network range
aclocalnet src fe80::/10              # RFC 4291 link-local (directly plugged) machines
acl SSL_ports port 443
acl Safe_ports port 80          # http
acl Safe_ports port 21          # ftp
acl Safe_ports port 443         # https
acl Safe_ports port 70          # gopher
acl Safe_ports port 210         # wais
acl Safe_ports port 1025-65535  # unregistered ports
acl Safe_ports port 280         # http-mgmt
acl Safe_ports port 488         # gss-http
acl Safe_ports port 591         # filemaker
acl Safe_ports port 777         # multiling http
http_access deny !Safe_ports
http_access deny CONNECT !SSL_ports
http_access allow localhost manager
http_access deny manager
include /etc/squid/conf.d/*.conf
http_access allow localhost
#http_access deny all
http_access allow all
http_port 3128
coredump_dir /var/spool/squid
refresh_pattern ^ftp:           1440    20%     10080
refresh_pattern ^gopher:        1440    0%      1440
refresh_pattern -i (/cgi-bin/|\?) 0     0%      0
refresh_pattern \/(Packages|Sources)(|\.bz2|\.gz|\.xz)$ 0 0% 0 refresh-ims
refresh_pattern \/Release(|\.gpg)$ 0 0% 0 refresh-ims
refresh_pattern \/InRelease$ 0 0% 0 refresh-ims
refresh_pattern \/(Translation-.*)(|\.bz2|\.gz|\.xz)$ 0 0% 0 refresh-ims
refresh_pattern .               0       20%     4320
http_upgrade_request_protocols OTHER allow all
debug_options ALL,1 11,3 31,3 65,3

源服务器响应日志

Mon, 21 Nov 2022 12:25:12 GMT engine intercepting request for path "/socket.io/"
Mon, 21 Nov 2022 12:25:12 GMT engine handling "GET" http request "/socket.io/?EIO=3&transport=polling&t=OIQ9alJ&b64=1"
Mon, 21 Nov 2022 12:25:12 GMT engine handshaking client "xbazbwzpPukK7rkVAAIH"
Mon, 21 Nov 2022 12:25:12 GMT engine:socket sending packet "open" ({"sid":"xbazbwzpPukK7rkVAAIH","upgrades":["websocket"],"pingInterval":15000,"pingTimeout":15000})
Mon, 21 Nov 2022 12:25:12 GMT engine:polling setting request
Mon, 21 Nov 2022 12:25:12 GMT engine:socket flushing buffer to transport
Mon, 21 Nov 2022 12:25:12 GMT engine:polling writing "97:0{"sid":"xbazbwzpPukK7rkVAAIH","upgrades":["websocket"],"pingInterval":15000,"pingTimeout":15000}"
Mon, 21 Nov 2022 12:25:12 GMT engine:socket executing batch send callback
Mon, 21 Nov 2022 12:25:12 GMT socket.io:server incoming connection with id xbazbwzpPukK7rkVAAIH
Mon, 21 Nov 2022 12:25:12 GMT socket.io:client connecting to namespace /
Mon, 21 Nov 2022 12:25:12 GMT socket.io:namespace adding socket to nsp /
Mon, 21 Nov 2022 12:25:12 GMT socket.io:socket socket connected - writing packet
Mon, 21 Nov 2022 12:25:12 GMT socket.io:socket joining room xbazbwzpPukK7rkVAAIH
Mon, 21 Nov 2022 12:25:12 GMT socket.io:client writing packet {"type":0,"nsp":"/"}
Mon, 21 Nov 2022 12:25:12 GMT socket.io-parser encoding packet {"type":0,"nsp":"/"}
Mon, 21 Nov 2022 12:25:12 GMT socket.io-parser encoded {"type":0,"nsp":"/"} as 0
Mon, 21 Nov 2022 12:25:12 GMT engine:socket sending packet "message" (0)
Mon, 21 Nov 2022 12:25:12 GMT socketio-auth removing socket from /
Mon, 21 Nov 2022 12:25:12 GMT socket.io:socket joined room xbazbwzpPukK7rkVAAIH
Mon, 21 Nov 2022 12:25:14 GMT engine:polling closing
Mon, 21 Nov 2022 12:25:14 GMT engine:polling transport not writable - buffering orderly close
Mon, 21 Nov 2022 12:25:14 GMT socket.io:client client close with reason ping timeout
Mon, 21 Nov 2022 12:25:14 GMT socket.io:socket closing socket - reason ping timeout
Mon, 21 Nov 2022 12:25:14 GMT socketio-auth Disconnecting socket XVQo3QXVeBEIFrezAAIC

Squid调试日志

2022/11/21 12:16:57.686 kid1| 11,2| client_side.cc(1357) parseHttpRequest: HTTP Client conn627 local=x.x.x.x:3128 remote=x.x.x.x:57396 FD 15 flags=1
2022/11/21 12:16:57.686 kid1| 11,2| client_side.cc(1358) parseHttpRequest: HTTP Client REQUEST:
---------
GET https://example.com/socket.io/?EIO=3&transport=polling&t=OIQ7i3h&b64=1 HTTP/1.1
user-agent: node-XMLHttpRequest
accept: */*
Host: example.com:443
connection: close


----------
2022/11/21 12:16:57.810 kid1| 11,3| http.cc(2498) httpStart: GET https://example.com/socket.io/?EIO=3&transport=polling&t=OIQ7i0i&b64=1
2022/11/21 12:16:57.810 kid1| 11,2| http.cc(2454) sendRequest: HTTP Server conn625 local=x.x.x.x:51642 remote=z.z.z.z:443 HIER_DIRECT FD 13 flags=1
2022/11/21 12:16:57.810 kid1| 11,2| http.cc(2455) sendRequest: HTTP Server REQUEST:
---------
GET /socket.io/?EIO=3&transport=polling&t=OIQ7i0i&b64=1 HTTP/1.1
User-Agent: node-XMLHttpRequest
Accept: */*
Host: example.com
Via: 1.1 squid-new (squid/5.6)
X-Forwarded-For: x.x.x.x
Cache-Control: max-age=0
Connection: keep-alive


----------
2022/11/21 12:16:57.963 kid1| 11,2| http.cc(1291) readReply: conn625 local=x.x.x.x:51642 remote=z.z.z.z:443 HIER_DIRECT FD 13 flags=1: read failure: (0) No error.
2022/11/21 12:16:57.964 kid1| 11,2| Stream.cc(279) sendStartOfMessage: HTTP Client conn622 local=x.x.x.x:3128 remote=x.x.x.x:49448 FD 11 flags=1
2022/11/21 12:16:57.964 kid1| 11,2| Stream.cc(280) sendStartOfMessage: HTTP Client REPLY:
---------
HTTP/1.1 502 Bad Gateway
Server: squid/5.6
Mime-Version: 1.0
Date: Mon, 21 Nov 2022 12:16:57 GMT
Content-Type: text/html;charset=utf-8
Content-Length: 3629
X-Squid-Error: ERR_READ_ERROR 0
Vary: Accept-Language
Content-Language: en
X-Cache: MISS from squid-new
X-Cache-Lookup: MISS from squid-new:3128
Via: 1.1 squid-new (squid/5.6)
Connection: close

排查与解决方向

从日志可见,源服务器已完成握手并尝试返回响应,但Squid读取服务器响应时触发ERR_READ_ERROR,导致返回502。可从以下方向排查:

  • 验证网络与SSL连接
    检查Squid到源服务器的网络连通性,用curl -x http://x.x.x.x:3128 https://example.com/socket.io/测试代理是否能正常获取响应;确认源服务器SSL证书有效,Squid可正常建立SSL连接。

  • 切换Socket.IO传输方式
    强制客户端优先使用websocket传输,避免polling模式的兼容性问题:

    var socket = proxy.connect('https://example.com', {
      transports: ['websocket']
    });
    
  • 替换代理包装器验证
    改用原生socket.io-client搭配代理配置,排除socket.io-proxy的问题:

    const io = require('socket.io-client');
    const socket = io('https://example.com', {
      agent: new (require('http').Agent)({
        proxy: {
          host: 'x.x.x.x',
          port: 3128
        }
      })
    });
    
  • 优化Squid配置

    • 增加超时设置,避免连接因响应缓慢被断开:
      connect_timeout 60 seconds
      read_timeout 300 seconds
      
    • 禁用socket.io路径的缓存,确保实时请求不被拦截:
      cache deny socket.io
      
    • 检查Host头处理逻辑,确认源服务器接受Squid转发时不带端口的Host头。

内容的提问来源于stack exchange,提问作者chingis

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.11 06:40:50