- Add isGitHubURL helper to detect github.com and all its subdomains
- rewriteURL now proxies absolute GitHub URLs, not just relative paths
- Injected script shares a unified domain list between rw (links) and
rfw (fetch/XHR), covering codeload.github.com, objects, avatars,
camo, user-images, etc.
- Click/form handlers now use rw() directly so absolute GitHub URLs
are also intercepted
via [HAPI](https://hapi.run)
Co-Authored-By: HAPI <[email protected]>
crypto.randomUUID() is only available in secure contexts (HTTPS).
GitHub's React code uses it, so we polyfill it in the injected script
for proxies served over HTTP.
via [HAPI](https://hapi.run)
Co-Authored-By: HAPI <[email protected]>
- Handle Request objects and URL objects passed to fetch()
- Patch EventSource and WebSocket constructors
- Move script injection to right after <head> so it runs before
the page's own JS captures fetch references
- Strip Transfer-Encoding when rewriting response body
- Add CORS headers to all proxied responses in ModifyResponse
via [HAPI](https://hapi.run)
Co-Authored-By: HAPI <[email protected]>
GitHub pages use JS-driven fetch/XMLHttpRequest calls that bypass
the proxy entirely, causing CORS errors. Monkey-patch both APIs in
the injected script to rewrite github.com/raw/githubusercontent/
api.github.com URLs to go through the proxy prefix.
via [HAPI](https://hapi.run)
Co-Authored-By: HAPI <[email protected]>
Upstream servers (e.g. GitHub) send Strict-Transport-Security and
Content-Security-Policy headers that cause browsers to upgrade HTTP
URLs to HTTPS. Strip those headers in ModifyResponse.
Also save the original request host/protocol in context before Director
mutates req.Host, then rewrite href attributes to explicit absolute URLs
(e.g. http://host/{token}/path) so the browser doesn't guess the scheme.
via [HAPI](https://hapi.run)
Co-Authored-By: HAPI <[email protected]>
JS injection fails on sites with strict Content-Security-Policy
(e.g. GitHub). Add golang.org/x/net/html-based server-side rewriting
of URL attributes (href/src/action/etc.) and CSS url() values before
response is sent. Keep JS injection as fallback for dynamic content.
via [HAPI](https://hapi.run)
Co-Authored-By: HAPI <[email protected]>
- Add ModifyResponse to DynamicProxy to inject token-prefix JS and
rewrite Location headers, same as GitHub proxy already did.
- Improve injectTokenPrefixScript to rewrite href/src/action on page
load and watch for dynamically added elements via MutationObserver.
- Replace hardcoded ../ login redirect with pathname-based calculation
so it works regardless of admin_path config.
via [HAPI](https://hapi.run)
Co-Authored-By: HAPI <[email protected]>
- Add `allowed_ips` to Link model with IPv4/IPv6 and CIDR support
- Validate client IP in proxy auth middleware against link whitelist
- Extract client IP from X-Forwarded-For / X-Real-Ip headers
- Fix copy button for non-HTTPS contexts via execCommand fallback
- Allow editing existing links (name, type, auth mode, rate limit, IPs)
- Add dedicated IP whitelist modal for quick editing
via [HAPI](https://hapi.run)
Co-Authored-By: HAPI <[email protected]>
- Docker Hub / GHCR / GitHub reverse proxy
- Web admin panel with link management
- Dynamic admin path, user and password config
- Rate limiting per link (dual/single auth mode)
- Docker and docker-compose deployment support
- GitHub Actions workflow for auto-publish to GHCR