Files
Deep-Package-Inspection/scripts/fix-apache-ssl.js
T

121 lines
6.1 KiB
JavaScript

// scripts/fix-apache-ssl.js
// ─────────────────────────────────────────────────────────────────────────────
// BackOne DPI — Fix Apache HTTPS 502 Bad Gateway
// The SSL VirtualHost needs mod_proxy configuration.
// cPanel uses Apache with .htaccess for proxy rules, but SSL VirtualHost
// may need specific directives to enable mod_proxy_http for the [P] flag.
// ─────────────────────────────────────────────────────────────────────────────
'use strict';
const { Client: SshClient } = require('ssh2');
const CONFIG = {
host: '103.185.47.52',
port: 2222,
username: 'adminbackend',
password: 'htEo7x6LsBQiEHHH',
};
const ROOT = '/home/adminbackend/web/demoplace.my.id/public_html';
const PM2 = '/home/adminbackend/.npm-global/bin/pm2';
const COMMANDS = [
// Investigate Apache config for SSL
`echo "=== APACHE MODULES ===" && apache2ctl -M 2>/dev/null | grep -i proxy | head -10 || httpd -M 2>/dev/null | grep -i proxy | head -10 || echo "Cannot check Apache modules"`,
// Check what's actually at the SSL port - is it Apache or Nginx or something else?
`echo "=== SSL PORT OWNER ===" && ss -tlnp | grep 443`,
// Check SSL log for 502 cause
`echo "=== SSL ACCESS LOG (last 10 502s) ===" && tail -50 /home/adminbackend/logs/demoplace.my.id-ssl_log 2>/dev/null | grep "502" | tail -10 || echo "No SSL log or no 502s in log"`,
`echo "=== SSL ERROR LOG (last 15) ===" && tail -15 /home/adminbackend/logs/demoplace.my.id-ssl_log 2>/dev/null || echo "No SSL log found"`,
// Find all log files for this domain
`echo "=== DOMAIN LOG FILES ===" && ls /home/adminbackend/logs/*demoplace* 2>/dev/null || echo "No domain-specific logs"`,
// Check Apache vhost config (cPanel stores them here)
`echo "=== APACHE SSL VHOST ===" && cat /etc/apache2/conf.d/userdata/ssl/2_4/adminbackend/demoplace.my.id/custom_subdirectory.conf 2>/dev/null || ls /etc/apache2/conf.d/userdata/ssl/2_4/adminbackend/ 2>/dev/null || echo "Cannot read Apache vhost config"`,
// Check all .htaccess files in path
`echo "=== ROOT HTACCESS ===" && cat ${ROOT}/.htaccess`,
// Check if mod_proxy is loaded
`echo "=== MOD_PROXY CHECK ===" && test -f /etc/apache2/mods-enabled/proxy.load && echo "mod_proxy ENABLED" || echo "mod_proxy NOT enabled"`,
`test -f /etc/apache2/mods-enabled/proxy_http.load && echo "mod_proxy_http ENABLED" || echo "mod_proxy_http NOT enabled"`,
// The issue may be cPanel's "nobody" user restriction
// Try using ProxyPass in .htaccess with explicit ProxyPassReverse
`echo "=== UPDATING .HTACCESS ===" && cat > ${ROOT}/.htaccess << 'EOF'
Options -MultiViews
RewriteEngine On
# Force HTTPS
RewriteCond %{HTTPS} !=on
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
# Proxy all requests to Next.js (port 3000)
RewriteRule ^(.*)$ http://127.0.0.1:3000/$1 [P,L,QSA]
ProxyPassReverse / http://127.0.0.1:3000/
EOF
echo ".htaccess updated"`,
// Read the new .htaccess to verify
`echo "=== NEW HTACCESS ===" && cat ${ROOT}/.htaccess`,
// Wait a moment for Apache to pick up changes
`sleep 2`,
// Test from server itself via HTTPS
`echo "=== HTTPS TEST FROM SERVER ===" && curl -sk -o /dev/null -w "HTTP %{http_code}" https://demoplace.my.id/ 2>&1`,
`echo "=== HTTPS LOGIN FROM SERVER ===" && curl -sk -o /dev/null -w "HTTP %{http_code}" https://demoplace.my.id/login 2>&1`,
// Check if it's a proxy timeout issue - try with verbose curl
`echo "=== VERBOSE HTTPS TEST ===" && curl -skv https://demoplace.my.id/ 2>&1 | grep -E "(<|>|\\*) " | head -20`,
// Alternative: check if cPanel has a NodeJS app manager entry interfering
`echo "=== CPANEL USERDATA ===" && ls /home/adminbackend/.cpanel/userdata/ 2>/dev/null`,
`cat /home/adminbackend/.cpanel/userdata/demoplace.my.id_SSL 2>/dev/null | head -30 || echo "No cPanel userdata for SSL"`,
`cat /home/adminbackend/.cpanel/userdata/demoplace.my.id 2>/dev/null | head -30 || echo "No cPanel userdata"`,
// Check Apache logs specifically for proxy errors
`echo "=== APACHE ERROR LOG ===" && tail -20 /var/log/apache2/error.log 2>/dev/null | grep -i "demoplace\|proxy\|502" | head -10 || echo "Cannot read Apache error log"`,
// PM2 processes still healthy?
`echo "=== PM2 STATUS ===" && ${PM2} list`,
`echo "=== FRONTEND HEALTH ===" && curl -s -o /dev/null -w "HTTP %{http_code}" http://127.0.0.1:3000/login`,
];
function runSsh(commands) {
return new Promise((resolve, reject) => {
const ssh = new SshClient();
ssh.on('ready', () => {
let i = 0;
function next() {
if (i >= commands.length) { ssh.end(); return; }
const cmd = commands[i++];
console.log(`\n$ ${cmd.substring(0, 100)}${cmd.length > 100 ? '...' : ''}`);
ssh.exec(cmd, (err, stream) => {
if (err) { console.error('[ERR]', err.message); next(); return; }
stream.on('data', d => process.stdout.write(d.toString()));
stream.stderr.on('data', d => { const t = d.toString(); if (!t.includes('npm warn') && !t.includes('notice')) process.stdout.write(t); });
stream.on('close', next);
});
}
next();
ssh.on('end', resolve);
});
ssh.on('error', reject);
ssh.connect({ ...CONFIG, readyTimeout: 30000 });
});
}
async function main() {
console.log('\n╔══════════════════════════════════════════════════════════╗');
console.log('║ BackOne DPI — Fix Apache HTTPS 502 Bad Gateway ║');
console.log('╚══════════════════════════════════════════════════════════╝\n');
await runSsh(COMMANDS);
console.log('\n✅ Apache SSL investigation complete!\n');
}
main().catch(err => { console.error('[FATAL]', err); process.exit(1); });