Skip to content

feat: support SOCKS5/SOCKS4 proxies via fetch-socks - #173

Open
motchie wants to merge 2 commits into
nulab:mainfrom
motchie:feature/socks5-proxy-support
Open

motchie wants to merge 2 commits into
nulab:mainfrom
motchie:feature/socks5-proxy-support

Conversation

@motchie

@motchie motchie commented Sep 30, 2026

Copy link
Copy Markdown

Summary

  • Detect a socks5://, socks5h://, socks4://, or socks4a:// URL in HTTPS_PROXY / HTTP_PROXY (falling back to a new ALL_PROXY / all_proxy) and route requests through a SOCKS dispatcher instead of EnvHttpProxyAgent when one is set.
  • Uses fetch-socks (MIT), which builds directly on undici's Dispatcher/connector API, composing with the existing logging interceptor the same way EnvHttpProxyAgent does today.
  • Adds an overrides pin (fetch-socks>undici) since fetch-socks depends on undici with the unpinned range >=7, which otherwise resolves a second, incompatible undici major inside the workspace.
  • Documents the new behavior in environment-variables.mdx, including a SOCKS5-over-SSH-tunnel example.
  • Known limitation (documented): NO_PROXY exclusions apply only to the HTTP(S) proxy path; SOCKS proxies route unconditionally.

Closes #164.

Test plan

  • vp check (format, lint, type check) passes
  • vp test — full suite passes (797 tests), including 6 new tests covering SOCKS5/SOCKS4a detection, default port, credentials parsing, HTTPS_PROXY/ALL_PROXY precedence, and invalid-URL fallback
  • vp run --filter @nulab/bee build — confirmed fetch-socks/socks bundle correctly into the built CLI
  • Manually ran the built CLI with HTTPS_PROXY=socks5://127.0.0.1:1 and confirmed (via debug logging) the request is routed through SocksClient and fails with ECONNREFUSED at the proxy, not the API host — proving the SOCKS path is wired up end-to-end

🤖 Generated with Claude Code

mochida.toru and others added 2 commits September 30, 2026 16:00
Set HTTPS_PROXY, HTTP_PROXY, or ALL_PROXY to a socks5://, socks5h://,
socks4://, or socks4a:// URL to route outbound requests through a SOCKS
proxy instead of a plain HTTP proxy. NO_PROXY exclusions do not apply
to SOCKS proxies.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Rebased onto main's toolchain migration (nulab#167): regenerate the lockfile,
move the fetch-socks>undici override into the overrides section (it had
landed under peerDependencyRules during the rebase's auto-merge), satisfy
the new tsgolint prefer-nullish-coalescing rule, and drop the now-redundant
vi.clearAllMocks() (clearMocks is on by default under vite-plus/test).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Support SOCKS5/SOCKS4 proxies for outbound requests

1 participant