Commit Graph
3 Commits
Author SHA1 Message Date
AgentandHAPI f13f294d04 fix: server-side HTML URL rewriting to bypass CSP blocking
Build and Push to GHCR / build-and-push (push) Has been cancelled
JS injection fails on sites with strict Content-Security-Policy
(e.g. GitHub). Add golang.org/x/net/html-based server-side rewriting
of URL attributes (href/src/action/etc.) and CSS url() values before
response is sent. Keep JS injection as fallback for dynamic content.

via [HAPI](https://hapi.run)

Co-Authored-By: HAPI <[email protected]>
2026-05-24 17:44:35 +08:00
AgentandHAPI f03eacaf20 fix: rewrite proxy links with token prefix and correct login redirect
Build and Push to GHCR / build-and-push (push) Has been cancelled
- Add ModifyResponse to DynamicProxy to inject token-prefix JS and
  rewrite Location headers, same as GitHub proxy already did.
- Improve injectTokenPrefixScript to rewrite href/src/action on page
  load and watch for dynamically added elements via MutationObserver.
- Replace hardcoded ../ login redirect with pathname-based calculation
  so it works regardless of admin_path config.

via [HAPI](https://hapi.run)

Co-Authored-By: HAPI <[email protected]>
2026-05-24 17:27:38 +08:00
AgentandHAPI fdbb824b7e feat: support arbitrary URL proxy via single token
Build and Push to GHCR / build-and-push (push) Has been cancelled
Allow proxying to any URL through the single-token auth path:
- /TOKEN/https://target.com/path
- /TOKEN/https:/target.com/path (browser-normalized)
- /TOKEN/target.com/path (auto-prefixed with https:// for known domains)

Also fix single-mode path handling that previously dropped
parts[2] when SplitN produced 3 parts.

via [HAPI](https://hapi.run)

Co-Authored-By: HAPI <[email protected]>
2026-05-24 16:22:02 +08:00