JS injection fails on sites with strict Content-Security-Policy
(e.g. GitHub). Add golang.org/x/net/html-based server-side rewriting
of URL attributes (href/src/action/etc.) and CSS url() values before
response is sent. Keep JS injection as fallback for dynamic content.
via [HAPI](https://hapi.run)
Co-Authored-By: HAPI <[email protected]>
- Add ModifyResponse to DynamicProxy to inject token-prefix JS and
rewrite Location headers, same as GitHub proxy already did.
- Improve injectTokenPrefixScript to rewrite href/src/action on page
load and watch for dynamically added elements via MutationObserver.
- Replace hardcoded ../ login redirect with pathname-based calculation
so it works regardless of admin_path config.
via [HAPI](https://hapi.run)
Co-Authored-By: HAPI <[email protected]>
Allow proxying to any URL through the single-token auth path:
- /TOKEN/https://target.com/path
- /TOKEN/https:/target.com/path (browser-normalized)
- /TOKEN/target.com/path (auto-prefixed with https:// for known domains)
Also fix single-mode path handling that previously dropped
parts[2] when SplitN produced 3 parts.
via [HAPI](https://hapi.run)
Co-Authored-By: HAPI <[email protected]>