Commit Graph
3 Commits
Author SHA1 Message Date
AgentandHAPI 6fcde70a26 fix: force href to absolute http URLs and strip HSTS/CSP headers
Build and Push to GHCR / build-and-push (push) Has been cancelled
Upstream servers (e.g. GitHub) send Strict-Transport-Security and
Content-Security-Policy headers that cause browsers to upgrade HTTP
URLs to HTTPS. Strip those headers in ModifyResponse.

Also save the original request host/protocol in context before Director
mutates req.Host, then rewrite href attributes to explicit absolute URLs
(e.g. http://host/{token}/path) so the browser doesn't guess the scheme.

via [HAPI](https://hapi.run)

Co-Authored-By: HAPI <[email protected]>
2026-05-24 21:01:48 +08:00
AgentandHAPI 163e625495 fix: remove unsupported regexp backreferences causing panic
Build and Push to GHCR / build-and-push (push) Has been cancelled
Go's regexp package uses RE2 syntax which does not support \1, \2
backreferences. Replace the regex-based refresh/CSS URL rewriting
with plain string scanning to avoid the init() panic.

via [HAPI](https://hapi.run)

Co-Authored-By: HAPI <[email protected]>
2026-05-24 19:26:13 +08:00
AgentandHAPI f13f294d04 fix: server-side HTML URL rewriting to bypass CSP blocking
Build and Push to GHCR / build-and-push (push) Has been cancelled
JS injection fails on sites with strict Content-Security-Policy
(e.g. GitHub). Add golang.org/x/net/html-based server-side rewriting
of URL attributes (href/src/action/etc.) and CSS url() values before
response is sent. Keep JS injection as fallback for dynamic content.

via [HAPI](https://hapi.run)

Co-Authored-By: HAPI <[email protected]>
2026-05-24 17:44:35 +08:00