srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/README.md
diff options
context:
space:
mode:
authorsrdusr <[email protected]>2026-02-24 19:30:00 +0200
committersrdusr <[email protected]>2026-02-24 19:30:00 +0200
commit66d00f513e30d0746c1d5b4cd3b0c4a34a243928 (patch)
tree37d785dbe2b0541ae7215969584d9d582a96bf37 /README.md
parent5200e412606c221fb618bd8e9a57a897553215d9 (diff)
downloadmitmux-66d00f513e30d0746c1d5b4cd3b0c4a34a243928.tar.gz
mitmux-66d00f513e30d0746c1d5b4cd3b0c4a34a243928.zip
Comparer: unified diff between two history entries
Next item off the "worth considering" list from the Burp/ZAP/Caido gap research. Mark an entry with 'c' (from the history list or detail view - no fetch yet, just remembers the ID), then 'c' on a different entry fetches both and opens a colored unified diff of either side's request or response, tab to switch between them. Unified (git-diff style: +/- prefixed lines) rather than Burp's side-by-side two-pane layout - a two-column view fights terminal width for anything but a wide window, and unified reuses the same scrollable viewport pattern already used everywhere else in this TUI rather than needing new layout machinery. Uses github.com/pmezard/go-difflib (SequenceMatcher-based, a tested port of Python's difflib) rather than hand-rolling LCS/Myers diff, which has real edge cases worth not reinventing. CRLF is normalized to LF before diffing - display-only, same reasoning as the JSON pretty-printer - so an HTTP/1.1 exact capture doesn't show every single line as changed purely from an invisible trailing \r. Verified live against two real, distinctly different captured POST requests (different form bodies, different Content-Length): the request diff correctly isolated exactly the two changed lines with the unchanged headers shown as context, colors confirmed via raw ANSI codes in the captured pane output (red 203 for removed, green 42 for added) rather than assumed from the code, and the response tab showed a correct independent diff of the two responses (Date header, JSON body). Also confirmed the "same entry marked twice" path shows a hint rather than silently doing something confusing.
Diffstat (limited to 'README.md')
-rw-r--r--README.md18
1 files changed, 15 insertions, 3 deletions
diff --git a/README.md b/README.md
index 70375c7..c3f2d92 100644
--- a/README.md
+++ b/README.md
@@ -48,6 +48,8 @@ list of what's deliberately not implemented (and why), see
audit trail.
- **Flagging**: mark an entry to revisit later (★), filterable via
`flagged:true`.
+- **Comparer**: mark one entry (`c`), then `c` on a different entry to
+ see a colored unified diff of either side's request or response.
- **Vi-modal editing**: the raw request editors (Repeater, Intruder)
are real modal editors - normal mode by default, `i`/`a`/`o`/etc. to
insert, `hjkl`, `dd`/`yy`/`p`, word motions, `gg`/`G`. See
@@ -121,6 +123,7 @@ below is enough to get going.
| `r` | open in Repeater |
| `i` | open in Intruder |
| `f` | toggle flag |
+| `c` | mark for comparison - press `c` on another entry to diff |
| `/` | search |
| `m` | match-and-replace rules |
| `q` | quit |
@@ -128,9 +131,18 @@ below is enough to get going.
### Detail view
`tab` switches request/response, `p` toggles pretty-printed JSON on the
-response (display-only - never touches the stored or resent bytes),
-`r`/`i` jump straight to Repeater/Intruder seeded from this entry, `esc`
-back.
+response (display-only - never touches the stored or resent bytes), `c`
+mark/compare (same as the history list), `r`/`i` jump straight to
+Repeater/Intruder seeded from this entry, `esc` back.
+
+### Comparer
+
+Reachable by pressing `c` on two different history entries (from either
+the list or detail view). Shows a colored unified diff - `diff -u`
+style, `+`/`-` lines - of the two entries' requests or responses,
+`tab` to switch between them. CRLF is normalized before diffing so an
+exact HTTP/1.1 capture doesn't show every line as changed purely from
+the invisible `\r`.
### Search syntax