A management system for HTTPS CONNECT proxy that forwards traffic over SOCKS5.
450
A self‑hosted manager for HTTPS CONNECT proxies that tunnel traffic through SOCKS5.
config.js (or via the UI) automatically respawn the affected proxy servers in seconds.certificate.crt) and private key (private.key) that your clients trustgit clone https://github.com/KevinWang15/socks-bridge.git
cd socks-bridge
mkdir -p certs
cp /path/to/certificate.crt certs/
cp /path/to/private.key certs/
config.js// config.js
module.exports = {
// TLS paths (inside the container)
tlsKey : '/app/certs/private.key',
tlsCert: '/app/certs/certificate.crt',
// When true, authentication failures return 200 OK with empty JSON
// instead of 407, masking the proxy but breaking browser compatibility
maskProxyAuth: false,
// Management UI credentials
admin: {
username: 'admin',
password: 'change‑me‑now!'
},
// One or more HTTPS proxy listeners
httpsProxyListeners: [
{
port : 8443, // HTTPS port exposed to clients
USERNAME: 'proxyUser', // (optional) basic‑auth credentials
PASSWORD: 'proxyPass', //
SOCKS_HOST: 'localhost', // Upstream SOCKS5 server
SOCKS_PORT: 1080,
SOCKS_USERNAME: '', // (optional)
SOCKS_PASSWORD: '' // (optional)
}
]
};
Tip: You may mount
config.jsfrom the host (see docker‑compose.yml) or bake it into a custom image.
docker compose up -d
Visit https://<host>:35443 (default) and log in with the admin credentials you set above.
| Key | Type | Description |
|---|---|---|
tlsKey / tlsCert | string | Absolute paths (inside the container) to your PEM‑encoded key and certificate. |
maskProxyAuth | boolean | When true, authentication failures return a 200 OK with empty JSON instead of 407 errors. This helps mask the server as a proxy but breaks standard browser proxy usage. Default: false. |
admin.username / admin.password | string | Credentials for the management UI (JWT‑based). |
httpsProxyListeners[] | array | Each object spawns an independent HTTPS CONNECT proxy. |
Add an optional timeouts object to relax server and socket timeouts and enable TCP keep‑alives to minimize premature disconnects (e.g., long‑lived CONNECT tunnels behind NATs).
Example config.js snippet:
timeouts: {
server: { requestTimeout: 0, headersTimeout: 86400000, keepAliveTimeout: 86400000, socketTimeout: 0 },
socket: { idleTimeout: 0, keepAlive: true, keepAliveInitialDelayMs: 60000 },
socks: { handshakeTimeoutMs: 86400000 }
}
Notes:
0 disables some timeouts in Node (e.g., requestTimeout, server socket timeouts).headersTimeout).| Field | Required | Notes |
|---|---|---|
port | ✅ | TCP port that the listener binds (must be unique). |
USERNAME / PASSWORD | ⬜ | If omitted, the listener is open (no basic‑auth). |
SOCKS_HOST / SOCKS_PORT | ⬜ | If omitted, traffic goes directly to the target host. |
SOCKS_USERNAME / SOCKS_PASSWORD | ⬜ | Credentials for the upstream SOCKS5 server (if it requires auth). |
Edit the file directly or use the Add Listener button in the dashboard. Changes are hot‑reloaded.

| Action | Description |
|---|---|
| Add Listener | Opens a modal to create a new HTTPS listener. |
| Edit / Delete | Modify or remove an existing listener. |
| Reload Configuration | Forces a manual reload (automatic reload also occurs on any change). |
| Copy Export Cmd | Copies export https_proxy=https://… to your clipboard for quick client setup. |
SOCKS Bridge is production‑grade — but your deployment practices determine how secure it really is.
# Install dev dependencies
npm install
# Auto‑reload backend during development
npm run dev
# Build the Docker image locally
docker build -t socks-bridge:dev .
├─ api/ # REST endpoints (auth & config)
├─ middleware/ # Express middlewares
├─ public/ # Static SPA assets (HTML/CSS/JS)
├─ utils/ # Helper modules (config, proxy, TLS)
├─ server.js # Entry point (Express + HTTPS)
└─ docker-compose.yml
Pull requests, bug reports, and feature ideas are welcome! Please open an issue to discuss your proposal before submitting large changes.
git checkout -b feat/my-featuregit commit -am 'Add new feature'git push origin feat/my-featureMIT
Content type
Image
Digest
sha256:df06c04f8…
Size
49.5 MB
Last updated
about 1 year ago
docker pull kevinwang15/socks-bridge