Files
Mirror-Proxy/internal/proxy/github.go
T
AgentandHAPI f13f294d04
Build and Push to GHCR / build-and-push (push) Has been cancelled
fix: server-side HTML URL rewriting to bypass CSP blocking
JS injection fails on sites with strict Content-Security-Policy
(e.g. GitHub). Add golang.org/x/net/html-based server-side rewriting
of URL attributes (href/src/action/etc.) and CSS url() values before
response is sent. Keep JS injection as fallback for dynamic content.

via [HAPI](https://hapi.run)

Co-Authored-By: HAPI <[email protected]>
2026-05-24 17:44:35 +08:00

255 lines
7.5 KiB
Go
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
package proxy
import (
"bytes"
"fmt"
"io"
"net/http"
"net/http/httputil"
"net/url"
"strings"
"time"
"mirror-proxy/internal/auth"
)
// NewGitHubProxy 创建 GitHub 主站反向代理
func NewGitHubProxy() http.Handler {
target, _ := url.Parse("https://github.com")
p := httputil.NewSingleHostReverseProxy(target)
p.Director = func(req *http.Request) {
req.URL.Scheme = target.Scheme
req.URL.Host = target.Host
req.Host = target.Host
req.Header.Set("Host", target.Host)
// 删除 Accept-Encoding,防止响应被压缩,便于修改 HTML
req.Header.Del("Accept-Encoding")
if req.Header.Get("User-Agent") == "" {
req.Header.Set("User-Agent", "MirrorProxy/1.0")
}
req.Header.Del("X-Forwarded-For")
}
p.ModifyResponse = func(resp *http.Response) error {
// 从请求上下文中获取 token 前缀
tokenPrefix := ""
if resp.Request != nil {
if prefix, ok := resp.Request.Context().Value(auth.TokenPrefixContextKey).(string); ok {
tokenPrefix = prefix
}
}
if tokenPrefix == "" {
return nil
}
// 重写 Location header
if loc := resp.Header.Get("Location"); loc != "" {
resp.Header.Set("Location", rewriteURL(loc, tokenPrefix))
}
// 对 HTML 响应做服务端 URL 重写 + 注入 JS 兜底
contentType := resp.Header.Get("Content-Type")
if strings.Contains(contentType, "text/html") && resp.Body != nil {
body, err := io.ReadAll(resp.Body)
if err != nil {
return err
}
resp.Body.Close()
// 1. 服务端重写所有已知 URL 属性(应对 CSP 禁止内联脚本的情况)
body = rewriteHTMLBody(body, tokenPrefix)
// 2. 注入 JS 处理动态添加的内容(无 CSP 时生效)
body = injectTokenPrefixScript(body, tokenPrefix)
resp.Body = io.NopCloser(bytes.NewReader(body))
resp.ContentLength = int64(len(body))
resp.Header.Set("Content-Length", fmt.Sprintf("%d", len(body)))
}
return nil
}
p.ErrorHandler = func(w http.ResponseWriter, r *http.Request, err error) {
w.Header().Set("Content-Type", "text/plain; charset=utf-8")
w.WriteHeader(http.StatusBadGateway)
fmt.Fprintf(w, "GitHub proxy error: %s", err.Error())
}
p.Transport = &http.Transport{
MaxIdleConns: 100,
MaxIdleConnsPerHost: 20,
IdleConnTimeout: 90 * time.Second,
TLSHandshakeTimeout: 10 * time.Second,
}
return p
}
// rewriteURL 重写 URL,在前面加上 token 前缀
func rewriteURL(u string, prefix string) string {
if u == "" || prefix == "" {
return u
}
// 已经是完整 URL(带 scheme)
if strings.HasPrefix(u, "http://") || strings.HasPrefix(u, "https://") {
return u
}
// 已经是带前缀的路径
if strings.HasPrefix(u, prefix+"/") || u == prefix {
return u
}
// 以 / 开头的绝对路径,加上前缀
if strings.HasPrefix(u, "/") {
return prefix + u
}
// 相对路径,不做处理
return u
}
// injectTokenPrefixScript 在 HTML 中注入 JS 脚本,重写所有链接使其包含 token 前缀
func injectTokenPrefixScript(body []byte, prefix string) []byte {
script := []byte(`<script>` +
`(function(){` +
`var p='` + prefix + `';` +
`function rw(v){return v&&v.startsWith('/')&&!v.startsWith(p+'/')&&v!==p?p+v:v};` +
`function fix(root){` +
`root.querySelectorAll&&root.querySelectorAll('a[href]').forEach(function(a){a.href=rw(a.getAttribute('href'))});` +
`root.querySelectorAll&&root.querySelectorAll('form[action]').forEach(function(f){f.action=rw(f.getAttribute('action'))});` +
`root.querySelectorAll&&root.querySelectorAll('[src]').forEach(function(el){var s=el.getAttribute('src');if(s&&s.startsWith('/')&&!s.startsWith(p+'/'))el.setAttribute('src',p+s)});` +
`}` +
`fix(document);` +
`if(window.MutationObserver){` +
`new MutationObserver(function(ms){ms.forEach(function(m){m.addedNodes.forEach(function(n){if(n.nodeType===1)fix(n)})})}).observe(document.documentElement||document.body,{childList:true,subtree:true});` +
`}` +
`document.addEventListener('click',function(e){` +
`var a=e.target.closest('a');` +
`if(!a)return;` +
`var h=a.getAttribute('href');` +
`if(h&&h.startsWith('/')&&!h.startsWith(p+'/')&&h!==p){` +
`e.preventDefault();` +
`location.href=p+h;` +
`}` +
`},true);` +
`document.addEventListener('submit',function(e){` +
`var f=e.target.closest('form');` +
`if(!f)return;` +
`var h=f.getAttribute('action');` +
`if(h&&h.startsWith('/')&&!h.startsWith(p+'/')&&h!==p){` +
`f.setAttribute('action',p+h);` +
`}` +
`},true);` +
`})();` +
`</script>`)
// 尝试在 </head> 前插入
if idx := bytes.Index(body, []byte("</head>")); idx != -1 {
return append(body[:idx], append(script, body[idx:]...)...)
}
// 或者在 <body> 标签后插入
if idx := bytes.Index(body, []byte("<body")); idx != -1 {
endIdx := bytes.Index(body[idx:], []byte(">"))
if endIdx != -1 {
pos := idx + endIdx + 1
return append(body[:pos], append(script, body[pos:]...)...)
}
}
// fallback:在文档开头插入
return append(script, body...)
}
// NewGitHubRawProxy 创建 GitHub Raw 反向代理
func NewGitHubRawProxy() http.Handler {
target, _ := url.Parse("https://raw.githubusercontent.com")
p := httputil.NewSingleHostReverseProxy(target)
p.Director = func(req *http.Request) {
req.URL.Scheme = target.Scheme
req.URL.Host = target.Host
req.Host = target.Host
req.Header.Set("Host", target.Host)
if req.Header.Get("User-Agent") == "" {
req.Header.Set("User-Agent", "MirrorProxy/1.0")
}
req.Header.Del("X-Forwarded-For")
}
p.ModifyResponse = func(resp *http.Response) error {
tokenPrefix := ""
if resp.Request != nil {
if prefix, ok := resp.Request.Context().Value(auth.TokenPrefixContextKey).(string); ok {
tokenPrefix = prefix
}
}
if tokenPrefix != "" {
if loc := resp.Header.Get("Location"); loc != "" {
resp.Header.Set("Location", rewriteURL(loc, tokenPrefix))
}
}
return nil
}
p.ErrorHandler = func(w http.ResponseWriter, r *http.Request, err error) {
w.Header().Set("Content-Type", "text/plain; charset=utf-8")
w.WriteHeader(http.StatusBadGateway)
fmt.Fprintf(w, "GitHub raw proxy error: %s", err.Error())
}
p.Transport = &http.Transport{
MaxIdleConns: 100,
MaxIdleConnsPerHost: 20,
IdleConnTimeout: 90 * time.Second,
TLSHandshakeTimeout: 10 * time.Second,
}
return p
}
// NewGitHubAPIProxy 创建 GitHub API 反向代理
func NewGitHubAPIProxy() http.Handler {
target, _ := url.Parse("https://api.github.com")
p := httputil.NewSingleHostReverseProxy(target)
p.Director = func(req *http.Request) {
req.URL.Scheme = target.Scheme
req.URL.Host = target.Host
req.Host = target.Host
req.Header.Set("Host", target.Host)
if req.Header.Get("User-Agent") == "" {
req.Header.Set("User-Agent", "MirrorProxy/1.0")
}
req.Header.Del("X-Forwarded-For")
}
p.ModifyResponse = func(resp *http.Response) error {
tokenPrefix := ""
if resp.Request != nil {
if prefix, ok := resp.Request.Context().Value(auth.TokenPrefixContextKey).(string); ok {
tokenPrefix = prefix
}
}
if tokenPrefix != "" {
if loc := resp.Header.Get("Location"); loc != "" {
resp.Header.Set("Location", rewriteURL(loc, tokenPrefix))
}
}
return nil
}
p.ErrorHandler = func(w http.ResponseWriter, r *http.Request, err error) {
w.Header().Set("Content-Type", "application/json")
w.WriteHeader(http.StatusBadGateway)
fmt.Fprintf(w, `{"message":"GitHub API proxy error: %s"}`, err.Error())
}
p.Transport = &http.Transport{
MaxIdleConns: 100,
MaxIdleConnsPerHost: 20,
IdleConnTimeout: 90 * time.Second,
TLSHandshakeTimeout: 10 * time.Second,
}
return p
}