The public /github/ route uses http.StripPrefix to remove /github
before forwarding to githubProxy. The auth proxy's github case was
missing this strip, causing /arkylin to be forwarded as
/github/arkylin → 404 on GitHub.
via [HAPI](https://hapi.run)
Co-Authored-By: HAPI <[email protected]>
GitHub download links (codeload.github.com) return 302 redirects to
objects.githubusercontent.com. When ReverseProxy passes the 302 through
to the browser, Chrome sees a HTTPS→HTTP redirect chain and shows
"redirected through an insecure connection" + ERR_CACHE_WRITE_FAILURE.
Add followRedirectTransport that uses http.Client to automatically
follow 3xx redirects before ReverseProxy sees the response. The browser
now receives the final ZIP content directly with a 200 status.
via [HAPI](https://hapi.run)
Co-Authored-By: HAPI <[email protected]>
- Add isGitHubURL helper to detect github.com and all its subdomains
- rewriteURL now proxies absolute GitHub URLs, not just relative paths
- Injected script shares a unified domain list between rw (links) and
rfw (fetch/XHR), covering codeload.github.com, objects, avatars,
camo, user-images, etc.
- Click/form handlers now use rw() directly so absolute GitHub URLs
are also intercepted
via [HAPI](https://hapi.run)
Co-Authored-By: HAPI <[email protected]>
crypto.randomUUID() is only available in secure contexts (HTTPS).
GitHub's React code uses it, so we polyfill it in the injected script
for proxies served over HTTP.
via [HAPI](https://hapi.run)
Co-Authored-By: HAPI <[email protected]>
- Handle Request objects and URL objects passed to fetch()
- Patch EventSource and WebSocket constructors
- Move script injection to right after <head> so it runs before
the page's own JS captures fetch references
- Strip Transfer-Encoding when rewriting response body
- Add CORS headers to all proxied responses in ModifyResponse
via [HAPI](https://hapi.run)
Co-Authored-By: HAPI <[email protected]>
GitHub pages use JS-driven fetch/XMLHttpRequest calls that bypass
the proxy entirely, causing CORS errors. Monkey-patch both APIs in
the injected script to rewrite github.com/raw/githubusercontent/
api.github.com URLs to go through the proxy prefix.
via [HAPI](https://hapi.run)
Co-Authored-By: HAPI <[email protected]>
Upstream servers (e.g. GitHub) send Strict-Transport-Security and
Content-Security-Policy headers that cause browsers to upgrade HTTP
URLs to HTTPS. Strip those headers in ModifyResponse.
Also save the original request host/protocol in context before Director
mutates req.Host, then rewrite href attributes to explicit absolute URLs
(e.g. http://host/{token}/path) so the browser doesn't guess the scheme.
via [HAPI](https://hapi.run)
Co-Authored-By: HAPI <[email protected]>
Go's regexp package uses RE2 syntax which does not support \1, \2
backreferences. Replace the regex-based refresh/CSS URL rewriting
with plain string scanning to avoid the init() panic.
via [HAPI](https://hapi.run)
Co-Authored-By: HAPI <[email protected]>
v0.55.0 required Go 1.25, breaking the Docker build which uses
golang:1.23-alpine. Downgrade to v0.33.0 which only needs Go 1.18
and still provides the html.Parse API we need.
via [HAPI](https://hapi.run)
Co-Authored-By: HAPI <[email protected]>
JS injection fails on sites with strict Content-Security-Policy
(e.g. GitHub). Add golang.org/x/net/html-based server-side rewriting
of URL attributes (href/src/action/etc.) and CSS url() values before
response is sent. Keep JS injection as fallback for dynamic content.
via [HAPI](https://hapi.run)
Co-Authored-By: HAPI <[email protected]>
- Add ModifyResponse to DynamicProxy to inject token-prefix JS and
rewrite Location headers, same as GitHub proxy already did.
- Improve injectTokenPrefixScript to rewrite href/src/action on page
load and watch for dynamically added elements via MutationObserver.
- Replace hardcoded ../ login redirect with pathname-based calculation
so it works regardless of admin_path config.
via [HAPI](https://hapi.run)
Co-Authored-By: HAPI <[email protected]>
- Add `allowed_ips` to Link model with IPv4/IPv6 and CIDR support
- Validate client IP in proxy auth middleware against link whitelist
- Extract client IP from X-Forwarded-For / X-Real-Ip headers
- Fix copy button for non-HTTPS contexts via execCommand fallback
- Allow editing existing links (name, type, auth mode, rate limit, IPs)
- Add dedicated IP whitelist modal for quick editing
via [HAPI](https://hapi.run)
Co-Authored-By: HAPI <[email protected]>
Allow proxying to any URL through the single-token auth path:
- /TOKEN/https://target.com/path
- /TOKEN/https:/target.com/path (browser-normalized)
- /TOKEN/target.com/path (auto-prefixed with https:// for known domains)
Also fix single-mode path handling that previously dropped
parts[2] when SplitN produced 3 parts.
via [HAPI](https://hapi.run)
Co-Authored-By: HAPI <[email protected]>
When admin config is updated with a new listen_addr or admin_path,
the server now automatically performs a graceful restart instead of
requiring the user to manually restart the service.
- cmd/main.go: refactor into a loop that supports graceful shutdown
and restart via http.Server.Shutdown
- internal/admin/handlers.go: add SetOnRestart callback, triggered
after config save when restart is required
- web/static/index.html: remove manual restart alert; auto-redirect
to new admin path or show toast if port changed
via [HAPI](https://hapi.run)
Co-Authored-By: HAPI <[email protected]>
- Add CONFIG_PATH env support to avoid Docker creating config.json as a directory
- Config Save() now auto-creates parent directories
- Update docker-compose.yml to mount ./config:/app/config
- Update README deployment docs accordingly
- Docker Hub / GHCR / GitHub reverse proxy
- Web admin panel with link management
- Dynamic admin path, user and password config
- Rate limiting per link (dual/single auth mode)
- Docker and docker-compose deployment support
- GitHub Actions workflow for auto-publish to GHCR