Commit Graph
24 Commits
Author SHA1 Message Date
AgentandHAPI 82ba0ff2d5 fix: strip /github prefix in auth proxy github case
Build and Push to GHCR / build-and-push (push) Has been cancelled
The public /github/ route uses http.StripPrefix to remove /github
before forwarding to githubProxy. The auth proxy's github case was
missing this strip, causing /arkylin to be forwarded as
/github/arkylin → 404 on GitHub.

via [HAPI](https://hapi.run)

Co-Authored-By: HAPI <[email protected]>
2026-05-25 00:08:03 +08:00
AgentandHAPI fc9e336e6b fix: auto-follow redirects in DynamicProxy to avoid HTTP downgrade warnings
Build and Push to GHCR / build-and-push (push) Has been cancelled
GitHub download links (codeload.github.com) return 302 redirects to
objects.githubusercontent.com. When ReverseProxy passes the 302 through
to the browser, Chrome sees a HTTPS→HTTP redirect chain and shows
"redirected through an insecure connection" + ERR_CACHE_WRITE_FAILURE.

Add followRedirectTransport that uses http.Client to automatically
follow 3xx redirects before ReverseProxy sees the response. The browser
now receives the final ZIP content directly with a 200 status.

via [HAPI](https://hapi.run)

Co-Authored-By: HAPI <[email protected]>
2026-05-25 00:04:35 +08:00
AgentandHAPI 62e2d3072f fix: rewrite all github subdomains (codeload, objects, avatars, etc.)
Build and Push to GHCR / build-and-push (push) Has been cancelled
- Add isGitHubURL helper to detect github.com and all its subdomains
- rewriteURL now proxies absolute GitHub URLs, not just relative paths
- Injected script shares a unified domain list between rw (links) and
  rfw (fetch/XHR), covering codeload.github.com, objects, avatars,
  camo, user-images, etc.
- Click/form handlers now use rw() directly so absolute GitHub URLs
  are also intercepted

via [HAPI](https://hapi.run)

Co-Authored-By: HAPI <[email protected]>
2026-05-24 23:29:54 +08:00
AgentandHAPI 2be1a3b220 fix: polyfill crypto.randomUUID for insecure HTTP contexts
Build and Push to GHCR / build-and-push (push) Has been cancelled
crypto.randomUUID() is only available in secure contexts (HTTPS).
GitHub's React code uses it, so we polyfill it in the injected script
for proxies served over HTTP.

via [HAPI](https://hapi.run)

Co-Authored-By: HAPI <[email protected]>
2026-05-24 23:12:38 +08:00
AgentandHAPI 1b8e24ddb1 fix: patch fetch Request objects, EventSource, WebSocket; inject script earlier
Build and Push to GHCR / build-and-push (push) Has been cancelled
- Handle Request objects and URL objects passed to fetch()
- Patch EventSource and WebSocket constructors
- Move script injection to right after <head> so it runs before
the page's own JS captures fetch references
- Strip Transfer-Encoding when rewriting response body
- Add CORS headers to all proxied responses in ModifyResponse

via [HAPI](https://hapi.run)

Co-Authored-By: HAPI <[email protected]>
2026-05-24 23:01:36 +08:00
AgentandHAPI 31b5031f86 fix: intercept fetch/XHR to route github requests back through proxy
Build and Push to GHCR / build-and-push (push) Has been cancelled
GitHub pages use JS-driven fetch/XMLHttpRequest calls that bypass
the proxy entirely, causing CORS errors. Monkey-patch both APIs in
the injected script to rewrite github.com/raw/githubusercontent/
api.github.com URLs to go through the proxy prefix.

via [HAPI](https://hapi.run)

Co-Authored-By: HAPI <[email protected]>
2026-05-24 22:22:07 +08:00
AgentandHAPI 6fcde70a26 fix: force href to absolute http URLs and strip HSTS/CSP headers
Build and Push to GHCR / build-and-push (push) Has been cancelled
Upstream servers (e.g. GitHub) send Strict-Transport-Security and
Content-Security-Policy headers that cause browsers to upgrade HTTP
URLs to HTTPS. Strip those headers in ModifyResponse.

Also save the original request host/protocol in context before Director
mutates req.Host, then rewrite href attributes to explicit absolute URLs
(e.g. http://host/{token}/path) so the browser doesn't guess the scheme.

via [HAPI](https://hapi.run)

Co-Authored-By: HAPI <[email protected]>
2026-05-24 21:01:48 +08:00
AgentandHAPI 163e625495 fix: remove unsupported regexp backreferences causing panic
Build and Push to GHCR / build-and-push (push) Has been cancelled
Go's regexp package uses RE2 syntax which does not support \1, \2
backreferences. Replace the regex-based refresh/CSS URL rewriting
with plain string scanning to avoid the init() panic.

via [HAPI](https://hapi.run)

Co-Authored-By: HAPI <[email protected]>
2026-05-24 19:26:13 +08:00
AgentandHAPI c1a1c06551 fix: downgrade golang.org/x/net to v0.33.0 for Go 1.23 compat
Build and Push to GHCR / build-and-push (push) Has been cancelled
v0.55.0 required Go 1.25, breaking the Docker build which uses
golang:1.23-alpine. Downgrade to v0.33.0 which only needs Go 1.18
and still provides the html.Parse API we need.

via [HAPI](https://hapi.run)

Co-Authored-By: HAPI <[email protected]>
2026-05-24 17:47:31 +08:00
AgentandHAPI f13f294d04 fix: server-side HTML URL rewriting to bypass CSP blocking
Build and Push to GHCR / build-and-push (push) Has been cancelled
JS injection fails on sites with strict Content-Security-Policy
(e.g. GitHub). Add golang.org/x/net/html-based server-side rewriting
of URL attributes (href/src/action/etc.) and CSS url() values before
response is sent. Keep JS injection as fallback for dynamic content.

via [HAPI](https://hapi.run)

Co-Authored-By: HAPI <[email protected]>
2026-05-24 17:44:35 +08:00
AgentandHAPI f03eacaf20 fix: rewrite proxy links with token prefix and correct login redirect
Build and Push to GHCR / build-and-push (push) Has been cancelled
- Add ModifyResponse to DynamicProxy to inject token-prefix JS and
  rewrite Location headers, same as GitHub proxy already did.
- Improve injectTokenPrefixScript to rewrite href/src/action on page
  load and watch for dynamically added elements via MutationObserver.
- Replace hardcoded ../ login redirect with pathname-based calculation
  so it works regardless of admin_path config.

via [HAPI](https://hapi.run)

Co-Authored-By: HAPI <[email protected]>
2026-05-24 17:27:38 +08:00
AgentandHAPI d6623fc150 feat: per-link IP whitelist, clipboard fallback, and link editing
Build and Push to GHCR / build-and-push (push) Has been cancelled
- Add `allowed_ips` to Link model with IPv4/IPv6 and CIDR support
- Validate client IP in proxy auth middleware against link whitelist
- Extract client IP from X-Forwarded-For / X-Real-Ip headers
- Fix copy button for non-HTTPS contexts via execCommand fallback
- Allow editing existing links (name, type, auth mode, rate limit, IPs)
- Add dedicated IP whitelist modal for quick editing

via [HAPI](https://hapi.run)

Co-Authored-By: HAPI <[email protected]>
2026-05-24 17:14:35 +08:00
AgentandHAPI b730708446 fix: return 404 on root path instead of redirecting to admin
Build and Push to GHCR / build-and-push (push) Has been cancelled
via [HAPI](https://hapi.run)

Co-Authored-By: HAPI <[email protected]>
2026-05-24 16:50:41 +08:00
AgentandHAPI bea74a6316 feat: add admin login page with session auth
Build and Push to GHCR / build-and-push (push) Has been cancelled
Replace HTTP Basic Auth with a dedicated login page using
cookie-based session authentication.

- Add web/static/login.html with form-based login UI
- Add in-memory session store with configurable timeout
- Add /api/auth/login, /api/auth/logout, /api/auth/me endpoints
- Replace BasicAuth middleware with SessionAuth
- Add session_timeout config field (default 24h)
- Remove listen_addr from settings UI

via [HAPI](https://hapi.run)

Co-Authored-By: HAPI <[email protected]>
2026-05-24 16:43:06 +08:00
AgentandHAPI fdbb824b7e feat: support arbitrary URL proxy via single token
Build and Push to GHCR / build-and-push (push) Has been cancelled
Allow proxying to any URL through the single-token auth path:
- /TOKEN/https://target.com/path
- /TOKEN/https:/target.com/path (browser-normalized)
- /TOKEN/target.com/path (auto-prefixed with https:// for known domains)

Also fix single-mode path handling that previously dropped
parts[2] when SplitN produced 3 parts.

via [HAPI](https://hapi.run)

Co-Authored-By: HAPI <[email protected]>
2026-05-24 16:22:02 +08:00
AgentandHAPI e8f760e510 feat: auto-restart server when listen addr or admin path changes
Build and Push to GHCR / build-and-push (push) Has been cancelled
When admin config is updated with a new listen_addr or admin_path,
the server now automatically performs a graceful restart instead of
requiring the user to manually restart the service.

- cmd/main.go: refactor into a loop that supports graceful shutdown
  and restart via http.Server.Shutdown
- internal/admin/handlers.go: add SetOnRestart callback, triggered
  after config save when restart is required
- web/static/index.html: remove manual restart alert; auto-redirect
  to new admin path or show toast if port changed

via [HAPI](https://hapi.run)

Co-Authored-By: HAPI <[email protected]>
2026-05-24 16:06:10 +08:00
Agent 086f326841 ci: add latest tag for default branch pushes
Build and Push to GHCR / build-and-push (push) Has been cancelled
Fix manifest unknown when pulling ghcr.io/arkylin/mirror-proxy:latest
2026-05-24 15:55:48 +08:00
Agent 090d264090 chore: change default port to 18800 and use relative paths in compose
Build and Push to GHCR / build-and-push (push) Has been cancelled
- docker-compose.yml: port 18800:8080, relative volume paths
- README.md: mkdir /opt/Mirror-Proxy && cd, then deploy
2026-05-24 15:52:07 +08:00
Agent 4027834a1f chore: use /opt/mirror-proxy as default data directory
Build and Push to GHCR / build-and-push (push) Has been cancelled
- docker-compose.yml: mount /opt/mirror-proxy/config and /opt/mirror-proxy/cache
- README.md: update deployment docs with /opt paths
2026-05-24 15:50:17 +08:00
Agent 44c8ff6a6f fix: mount config directory instead of file for Docker Compose
Build and Push to GHCR / build-and-push (push) Has been cancelled
- Add CONFIG_PATH env support to avoid Docker creating config.json as a directory
- Config Save() now auto-creates parent directories
- Update docker-compose.yml to mount ./config:/app/config
- Update README deployment docs accordingly
2026-05-24 15:44:29 +08:00
Agent 45da2d1d0c docs: rewrite Docker Compose deployment guide with copy-paste commands
Build and Push to GHCR / build-and-push (push) Has been cancelled
2026-05-24 15:40:15 +08:00
Agent 3695d04a2c docs: update GHCR image address to arkylin/mirror-proxy
Build and Push to GHCR / build-and-push (push) Has been cancelled
2026-05-24 15:38:07 +08:00
Agent d48e31ba77 fix: downgrade go.mod version to 1.23 for docker build compatibility
Build and Push to GHCR / build-and-push (push) Has been cancelled
The golang:1.23-alpine image cannot build with go 1.26.3 directive.
Align go.mod with the Dockerfile builder image version.
2026-05-24 15:35:33 +08:00
Agent 9223e35164 feat: init mirror-proxy project
Build and Push to GHCR / build-and-push (push) Has been cancelled
- Docker Hub / GHCR / GitHub reverse proxy
- Web admin panel with link management
- Dynamic admin path, user and password config
- Rate limiting per link (dual/single auth mode)
- Docker and docker-compose deployment support
- GitHub Actions workflow for auto-publish to GHCR
2026-05-24 15:27:45 +08:00