Upstream servers (e.g. GitHub) send Strict-Transport-Security and
Content-Security-Policy headers that cause browsers to upgrade HTTP
URLs to HTTPS. Strip those headers in ModifyResponse.
Also save the original request host/protocol in context before Director
mutates req.Host, then rewrite href attributes to explicit absolute URLs
(e.g. http://host/{token}/path) so the browser doesn't guess the scheme.
via [HAPI](https://hapi.run)
Co-Authored-By: HAPI <[email protected]>
Go's regexp package uses RE2 syntax which does not support \1, \2
backreferences. Replace the regex-based refresh/CSS URL rewriting
with plain string scanning to avoid the init() panic.
via [HAPI](https://hapi.run)
Co-Authored-By: HAPI <[email protected]>
JS injection fails on sites with strict Content-Security-Policy
(e.g. GitHub). Add golang.org/x/net/html-based server-side rewriting
of URL attributes (href/src/action/etc.) and CSS url() values before
response is sent. Keep JS injection as fallback for dynamic content.
via [HAPI](https://hapi.run)
Co-Authored-By: HAPI <[email protected]>