From 0f9946e6ca3dac3c03679e8f77c25689cf86a1ad Mon Sep 17 00:00:00 2001 From: bonamin Date: Mon, 28 Sep 2026 08:28:27 +0300 Subject: [PATCH] fix(proxy): forward WebSocket upgrades and disable buffering in proxy configs The nginx config written by install.sh proxied waiter.*, manager.* and the IP default_server without proxy_http_version 1.1 or Upgrade/Connection headers, so /api/ws/connect never upgraded and live events (new orders, KDS status, chat, phone calls) never reached waiters or the manager. The repo's nginx-proxy/nginx.conf had the same gap on the manager block. Both configs now use a $connection_upgrade map, 1h read/send timeouts and proxy_buffering off (SSE) on every proxied location. Verified with nginx -t and a header-echo upstream: old config strips Upgrade, new one forwards it. Existing sites: copy the new install.sh, re-run it, restart the proxy. Co-Authored-By: Claude Opus 5.5 --- install.sh | 34 ++++++++++++++++++++++++++++++++++ nginx-proxy/nginx.conf | 20 ++++++++++++++++++-- 2 files changed, 52 insertions(+), 2 deletions(-) diff --git a/install.sh b/install.sh index 55a41ae..9604cb3 100644 --- a/install.sh +++ b/install.sh @@ -54,6 +54,14 @@ fi # ── 3. Write nginx-proxy/nginx.conf ────────────────────────────────────────── echo "[ 3/5 ] Writing nginx proxy config..." cat > "$SCRIPT_DIR/nginx-proxy/nginx.conf" << 'EOF' +# Generated by install.sh — keep in sync with nginx-proxy/nginx.conf in the repo. +# Every proxied location must forward WebSocket upgrades (/api/ws/connect) and +# must not buffer (SSE), otherwise live events never reach waiters / KDS. +map $http_upgrade $connection_upgrade { + default upgrade; + '' close; +} + server { listen 80; return 301 https://$host$request_uri; @@ -70,10 +78,16 @@ server { location / { proxy_pass http://waiter_pwa:80; + proxy_http_version 1.1; + proxy_set_header Upgrade $http_upgrade; + proxy_set_header Connection $connection_upgrade; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; + proxy_read_timeout 3600s; + proxy_send_timeout 3600s; + proxy_buffering off; } } @@ -88,10 +102,16 @@ server { location / { proxy_pass http://manager_dashboard:80; + proxy_http_version 1.1; + proxy_set_header Upgrade $http_upgrade; + proxy_set_header Connection $connection_upgrade; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; + proxy_read_timeout 3600s; + proxy_send_timeout 3600s; + proxy_buffering off; } } @@ -100,21 +120,35 @@ server { ssl_certificate /etc/nginx/certs/cert.pem; ssl_certificate_key /etc/nginx/certs/key.pem; + ssl_protocols TLSv1.2 TLSv1.3; + ssl_ciphers HIGH:!aNULL:!MD5; location /api/ { proxy_pass http://backend:8000; + proxy_http_version 1.1; + proxy_set_header Upgrade $http_upgrade; + proxy_set_header Connection $connection_upgrade; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; + proxy_read_timeout 3600s; + proxy_send_timeout 3600s; + proxy_buffering off; } location / { proxy_pass http://waiter_pwa:80; + proxy_http_version 1.1; + proxy_set_header Upgrade $http_upgrade; + proxy_set_header Connection $connection_upgrade; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; + proxy_read_timeout 3600s; + proxy_send_timeout 3600s; + proxy_buffering off; } } EOF diff --git a/nginx-proxy/nginx.conf b/nginx-proxy/nginx.conf index da62caa..1f295ae 100644 --- a/nginx-proxy/nginx.conf +++ b/nginx-proxy/nginx.conf @@ -1,3 +1,11 @@ +# Repo/dev proxy config. install.sh writes its own copy on client sites — keep both in sync. +# Every proxied location must forward WebSocket upgrades (/api/ws/connect) and +# must not buffer (SSE), otherwise live events never reach waiters / KDS. +map $http_upgrade $connection_upgrade { + default upgrade; + '' close; +} + server { listen 80; return 301 https://$host$request_uri; @@ -16,12 +24,14 @@ server { proxy_pass http://waiter_pwa:80; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; - proxy_set_header Connection $http_connection; + proxy_set_header Connection $connection_upgrade; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; - proxy_read_timeout 3600; + proxy_read_timeout 3600s; + proxy_send_timeout 3600s; + proxy_buffering off; } } @@ -36,9 +46,15 @@ server { location / { proxy_pass http://manager_dashboard:80; + proxy_http_version 1.1; + proxy_set_header Upgrade $http_upgrade; + proxy_set_header Connection $connection_upgrade; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; + proxy_read_timeout 3600s; + proxy_send_timeout 3600s; + proxy_buffering off; } }