srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/PLAN.md
diff options
context:
space:
mode:
authorsrdusr <[email protected]>2026-03-17 09:44:00 +0200
committersrdusr <[email protected]>2026-03-17 09:44:00 +0200
commit80354144ddc39d33204ab47153c33bdb111b5544 (patch)
tree39247cadcfe0e375437c434cdc4a548c0196aa11 /PLAN.md
parent66d00f513e30d0746c1d5b4cd3b0c4a34a243928 (diff)
downloadmitmux-80354144ddc39d33204ab47153c33bdb111b5544.tar.gz
mitmux-80354144ddc39d33204ab47153c33bdb111b5544.zip
Standalone Decoder: URL/Base64/Hex/HTML encode & decode
First of the remaining "worth considering" items. A self-contained tool ('d' from the history list, not seeded from any entry - this is for arbitrary snippets, pasted tokens, encoded parameter values) with a vi-modal input pane and a live output pane that updates on every keystroke and every transform switch (tab/shift+tab cycles through the 8 transforms). decoder.go is pure logic, deliberately kept separate from the TUI wiring so it's directly testable: urlEncodeAll implements strict RFC 3986 percent-encoding (space -> %20) rather than using Go's url.QueryEscape, whose form-encoding behavior (space -> '+') isn't what "URL encode" means to a pentester reaching for this tool. Base64 decode tries standard/URL-safe/padded/unpadded encodings in turn rather than requiring the user to know which one they're looking at - real pasted data is as likely to be one as the other. Decode failures return a visible "(error: ...)" placeholder rather than blanking the output, so a bad guess at the transform is obviously wrong rather than looking like nothing happened. decoder_test.go covers each transform directly, three "this input isn't valid for this transform" error cases, and a round-trip matrix (all 4 encode/decode pairs against 5 inputs chosen to be awkward for at least one encoding - spaces, slashes, HTML-special characters, empty string, embedded newlines) confirming encode-then-decode always recovers the original. Single-transform only, not chained/pipelined like Burp's Decoder - v1 scope, tracked in PLAN.md. Verified live: typed text and watched the output pane update in real time; confirmed URL-encoding, then cycled to Base64 via tab and watched it re-encode the same input live; confirmed the active-transform highlighting via raw ANSI codes in the captured pane; fed invalid input to Base64 decode and confirmed the error placeholder renders instead of silently showing stale output; confirmed esc correctly backs out to the history list.
Diffstat (limited to 'PLAN.md')
-rw-r--r--PLAN.md21
1 files changed, 15 insertions, 6 deletions
diff --git a/PLAN.md b/PLAN.md
index 22ab6a4..67e0e77 100644
--- a/PLAN.md
+++ b/PLAN.md
@@ -99,13 +99,22 @@ anything but a narrow window, and unified reuses the same scrollable-
viewport pattern already used everywhere else in the TUI. CRLF is
normalized to LF before diffing (display-only, same reasoning as the
JSON pretty-printer) so an HTTP/1.1 exact capture doesn't show every
-line as changed from an invisible trailing \r.
+line as changed from an invisible trailing \r; a standalone Decoder
+tool ('d') - URL/Base64/Hex/HTML encode and decode, live output as you
+type, tab to cycle transforms. Deliberately single-transform, not
+chained/pipelined like Burp's Decoder - v1 scope, and pipeline-building
+UI is real added complexity for a feature that's already useful without
+it. Base64 decode tries standard/URL-safe/padded/unpadded variants in
+turn rather than making the user pick, since real pasted data is as
+likely to be one as the other. URL encode/decode uses strict RFC 3986
+percent-encoding (space <-> %20), not Go's url.QueryEscape's form-
+encoding behavior (space <-> '+'), since "URL encode" for a pentester
+almost always means the former.
-Still open from "worth considering": a standalone encoder/decoder
-utility, multiple concurrent Repeater tabs, Intruder payload processing
-(encoding/case rules) and grep-match/grep-extract on results, CA install
-UX per OS, multiple proxy listeners and upstream proxy chaining. None
-of these are started yet.
+Still open from "worth considering": multiple concurrent Repeater tabs,
+Intruder payload processing (encoding/case rules) and grep-match/
+grep-extract on results, CA install UX per OS, multiple proxy listeners
+and upstream proxy chaining. None of these are started yet.
Skipped deliberately (from the research, matches this tool's stated
scope): active/passive vulnerability scanning, plugin marketplace,