srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/PLAN.md
diff options
context:
space:
mode:
authorsrdusr <[email protected]>2026-02-24 19:30:00 +0200
committersrdusr <[email protected]>2026-02-24 19:30:00 +0200
commit66d00f513e30d0746c1d5b4cd3b0c4a34a243928 (patch)
tree37d785dbe2b0541ae7215969584d9d582a96bf37 /PLAN.md
parent5200e412606c221fb618bd8e9a57a897553215d9 (diff)
downloadmitmux-66d00f513e30d0746c1d5b4cd3b0c4a34a243928.tar.gz
mitmux-66d00f513e30d0746c1d5b4cd3b0c4a34a243928.zip
Comparer: unified diff between two history entries
Next item off the "worth considering" list from the Burp/ZAP/Caido gap research. Mark an entry with 'c' (from the history list or detail view - no fetch yet, just remembers the ID), then 'c' on a different entry fetches both and opens a colored unified diff of either side's request or response, tab to switch between them. Unified (git-diff style: +/- prefixed lines) rather than Burp's side-by-side two-pane layout - a two-column view fights terminal width for anything but a wide window, and unified reuses the same scrollable viewport pattern already used everywhere else in this TUI rather than needing new layout machinery. Uses github.com/pmezard/go-difflib (SequenceMatcher-based, a tested port of Python's difflib) rather than hand-rolling LCS/Myers diff, which has real edge cases worth not reinventing. CRLF is normalized to LF before diffing - display-only, same reasoning as the JSON pretty-printer - so an HTTP/1.1 exact capture doesn't show every single line as changed purely from an invisible trailing \r. Verified live against two real, distinctly different captured POST requests (different form bodies, different Content-Length): the request diff correctly isolated exactly the two changed lines with the unchanged headers shown as context, colors confirmed via raw ANSI codes in the captured pane output (red 203 for removed, green 42 for added) rather than assumed from the code, and the response tab showed a correct independent diff of the two responses (Date header, JSON body). Also confirmed the "same entry marked twice" path shows a hint rather than silently doing something confusing.
Diffstat (limited to 'PLAN.md')
-rw-r--r--PLAN.md21
1 files changed, 15 insertions, 6 deletions
diff --git a/PLAN.md b/PLAN.md
index ca379e9..22ab6a4 100644
--- a/PLAN.md
+++ b/PLAN.md
@@ -90,13 +90,22 @@ structured search filters (status:, source:, flagged:) alongside the
existing FTS5 text search; a flagged marker (★) for "revisit this" -
deliberately simpler than full free-text notes/comments, which would
need their own text-input overlay for comparatively modest extra value
-over a boolean; noted as a real follow-up, not dropped silently.
+over a boolean; noted as a real follow-up, not dropped silently; a
+Comparer tool - mark an entry with 'c' (from history list or detail
+view), 'c' again on a different entry opens a unified diff (git-diff
+style, colored) of either side's request or response. Unified rather
+than Burp's side-by-side: a two-column layout fights terminal width for
+anything but a narrow window, and unified reuses the same scrollable-
+viewport pattern already used everywhere else in the TUI. CRLF is
+normalized to LF before diffing (display-only, same reasoning as the
+JSON pretty-printer) so an HTTP/1.1 exact capture doesn't show every
+line as changed from an invisible trailing \r.
-Still open from "worth considering": a Comparer (diff) tool, a
-standalone encoder/decoder utility, multiple concurrent Repeater tabs,
-Intruder payload processing (encoding/case rules) and grep-match/
-grep-extract on results, CA install UX per OS, multiple proxy listeners
-and upstream proxy chaining. None of these are started yet.
+Still open from "worth considering": a standalone encoder/decoder
+utility, multiple concurrent Repeater tabs, Intruder payload processing
+(encoding/case rules) and grep-match/grep-extract on results, CA install
+UX per OS, multiple proxy listeners and upstream proxy chaining. None
+of these are started yet.
Skipped deliberately (from the research, matches this tool's stated
scope): active/passive vulnerability scanning, plugin marketplace,