srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/PLUGINS.md
diff options
context:
space:
mode:
authorsrdusr <[email protected]>2026-08-25 15:58:00 +0200
committersrdusr <[email protected]>2026-08-25 15:58:00 +0200
commit9e94bcbc939afd38b45f9ef42e1b1666fafd8d45 (patch)
tree88a36226ee332c74e2dba98a9568a3a09ad074a8 /PLUGINS.md
parentdde73a349a68f942a5bd89b27ac980d7973148e0 (diff)
downloadmitmux-9e94bcbc939afd38b45f9ef42e1b1666fafd8d45.tar.gz
mitmux-9e94bcbc939afd38b45f9ef42e1b1666fafd8d45.zip
Wire-format JSON tag consistency fix, and the first real plugin
Writing PLUGINS.md as an authoritative external spec surfaced a real, pre-existing bug: store.Summary/Entry/EntryTag/WSMessage, rules.Rule, scope.Rule, and clientcert.Cert had no JSON struct tags at all, so Go's default marshaling serialized them PascalCase ("ID", "StartedAt") while the rest of the protocol (EntryDetail's own fields, every Request/Response wrapper field) uses snake_case. Confirmed live against a real daemon before touching anything: a raw socket "list" request came back with "ID"/"StartedAt"/"StatusCode", exactly the mismatch suspected. Nothing outside this repo's own Go code consumes this wire format yet, so this was a free, purely additive fix rather than something to work around - every affected struct now tags snake_case consistently. plugins/authcheck is the first real plugin: an Autorize-style authorization checker. For every proxied request carrying an Authorization or Cookie header, resends it with that header stripped and compares status classes - a resend that still succeeds where the original did too is a likely missing-function-level-access-control bug, tagged authcheck:bypass with structured detail. Deliberately speaks the wire protocol directly (its own local request/response/ summary/entryDetail structs mirroring the real ones field-for-field, not imported from internal/ipc) rather than taking the shortcut a Go plugin could - proof the documented protocol is actually sufficient on its own, since that's all a non-Go plugin author has to work with. Verified live end to end: a real daemon, a real Python origin with one endpoint that looks like it enforces auth but doesn't (vulnerable by design) and one that actually does (the control case) - the broken endpoint was correctly tagged, the secure one correctly left alone, no false positive, confirmed both via the stored tag data directly and visually in the TUI (tmux, real keystrokes): the Tags column badge, T's tag list, and the tag detail view's JSON-colorized data (ANSI-verified, not eyeballed) all showing the plugin's actual findings.
Diffstat (limited to 'PLUGINS.md')
-rw-r--r--PLUGINS.md8
1 files changed, 8 insertions, 0 deletions
diff --git a/PLUGINS.md b/PLUGINS.md
index bb46461..630f211 100644
--- a/PLUGINS.md
+++ b/PLUGINS.md
@@ -11,6 +11,14 @@ Go), and means a plugin can be developed and tested against the exact
same socket the TUI is already using, with `mitmux` itself open in
another terminal watching what happens in real time.
+`plugins/authcheck` is a real, working reference implementation - an
+Autorize-style authorization checker (resends a captured request with
+its auth header stripped, tags the entry if the response still
+succeeds) - written to only ever exercise what's documented on this
+page, not any of mitmux's own internal Go packages, specifically so it
+proves this protocol is sufficient on its own. Worth reading alongside
+this document, or just copying as a starting point.
+
## Connecting
The socket path is the same one `mitmux -socket` and `mitmuxd -socket`