diff options
| author | srdusr <[email protected]> | 2026-03-17 09:44:00 +0200 |
|---|---|---|
| committer | srdusr <[email protected]> | 2026-03-17 09:44:00 +0200 |
| commit | 80354144ddc39d33204ab47153c33bdb111b5544 (patch) | |
| tree | 39247cadcfe0e375437c434cdc4a548c0196aa11 /PLAN.md | |
| parent | 66d00f513e30d0746c1d5b4cd3b0c4a34a243928 (diff) | |
| download | mitmux-80354144ddc39d33204ab47153c33bdb111b5544.tar.gz mitmux-80354144ddc39d33204ab47153c33bdb111b5544.zip | |
Standalone Decoder: URL/Base64/Hex/HTML encode & decode
First of the remaining "worth considering" items. A self-contained
tool ('d' from the history list, not seeded from any entry - this is
for arbitrary snippets, pasted tokens, encoded parameter values) with
a vi-modal input pane and a live output pane that updates on every
keystroke and every transform switch (tab/shift+tab cycles through the
8 transforms).
decoder.go is pure logic, deliberately kept separate from the TUI
wiring so it's directly testable: urlEncodeAll implements strict RFC
3986 percent-encoding (space -> %20) rather than using Go's
url.QueryEscape, whose form-encoding behavior (space -> '+') isn't what
"URL encode" means to a pentester reaching for this tool. Base64 decode
tries standard/URL-safe/padded/unpadded encodings in turn rather than
requiring the user to know which one they're looking at - real pasted
data is as likely to be one as the other. Decode failures return a
visible "(error: ...)" placeholder rather than blanking the output, so
a bad guess at the transform is obviously wrong rather than looking
like nothing happened.
decoder_test.go covers each transform directly, three "this input isn't
valid for this transform" error cases, and a round-trip matrix (all 4
encode/decode pairs against 5 inputs chosen to be awkward for at least
one encoding - spaces, slashes, HTML-special characters, empty string,
embedded newlines) confirming encode-then-decode always recovers the
original.
Single-transform only, not chained/pipelined like Burp's Decoder - v1
scope, tracked in PLAN.md.
Verified live: typed text and watched the output pane update in real
time; confirmed URL-encoding, then cycled to Base64 via tab and watched
it re-encode the same input live; confirmed the active-transform
highlighting via raw ANSI codes in the captured pane; fed invalid input
to Base64 decode and confirmed the error placeholder renders instead of
silently showing stale output; confirmed esc correctly backs out to the
history list.
Diffstat (limited to 'PLAN.md')
| -rw-r--r-- | PLAN.md | 21 |
1 files changed, 15 insertions, 6 deletions
@@ -99,13 +99,22 @@ anything but a narrow window, and unified reuses the same scrollable- viewport pattern already used everywhere else in the TUI. CRLF is normalized to LF before diffing (display-only, same reasoning as the JSON pretty-printer) so an HTTP/1.1 exact capture doesn't show every -line as changed from an invisible trailing \r. +line as changed from an invisible trailing \r; a standalone Decoder +tool ('d') - URL/Base64/Hex/HTML encode and decode, live output as you +type, tab to cycle transforms. Deliberately single-transform, not +chained/pipelined like Burp's Decoder - v1 scope, and pipeline-building +UI is real added complexity for a feature that's already useful without +it. Base64 decode tries standard/URL-safe/padded/unpadded variants in +turn rather than making the user pick, since real pasted data is as +likely to be one as the other. URL encode/decode uses strict RFC 3986 +percent-encoding (space <-> %20), not Go's url.QueryEscape's form- +encoding behavior (space <-> '+'), since "URL encode" for a pentester +almost always means the former. -Still open from "worth considering": a standalone encoder/decoder -utility, multiple concurrent Repeater tabs, Intruder payload processing -(encoding/case rules) and grep-match/grep-extract on results, CA install -UX per OS, multiple proxy listeners and upstream proxy chaining. None -of these are started yet. +Still open from "worth considering": multiple concurrent Repeater tabs, +Intruder payload processing (encoding/case rules) and grep-match/ +grep-extract on results, CA install UX per OS, multiple proxy listeners +and upstream proxy chaining. None of these are started yet. Skipped deliberately (from the research, matches this tool's stated scope): active/passive vulnerability scanning, plugin marketplace, |