diff options
| author | srdusr <[email protected]> | 2026-07-31 16:07:00 +0200 |
|---|---|---|
| committer | srdusr <[email protected]> | 2026-07-31 16:07:00 +0200 |
| commit | 9b630b2cbf9206855534668ebaaaee255cabedd4 (patch) | |
| tree | b4c45860ae3e52eb8909cb868649c07c6c93e1a6 /README.md | |
| parent | 384573a2dc5e3b8e2a7bdfe2ce949f2c52ba2c52 (diff) | |
| download | mitmux-9b630b2cbf9206855534668ebaaaee255cabedd4.tar.gz mitmux-9b630b2cbf9206855534668ebaaaee255cabedd4.zip | |
History sorting, status color-coding, and JSON syntax highlighting
Filtering already existed (FTS5 search plus status:/source:/flagged:
and column filters). Sorting and highlighting didn't, at all.
Sorting: o/O cycle and reverse the sort column (status, size, time
taken, method, host, path) applied client-side on top of whatever
order List/Search already returned. refreshTable() reorders m.entries
itself, not just what's rendered - every "act on the selected row" key
handler indexes m.table.Cursor() straight into m.entries with no
indirection, so keeping the two in identical order sidesteps an entire
class of "highlighted row and actual target silently disagree" bugs
rather than updating every one of those call sites.
JSON syntax highlighting (cmd/mitmux/jsoncolor.go): walks the token
stream via json.Decoder.Token() with an explicit stack, not recursive
calls, so depth is bounded by memory rather than Go's call stack for
adversarial nesting. Every string re-escaped via json.Marshal before
writing, which is also why the colorized output is deliberately never
run through sanitizeControl afterward (unlike every other raw-text
view here): JSON's own encoding rules already forbid a literal control
character in a string, so re-marshaling neutralizes one as a side
effect of producing valid JSON - running sanitizeControl on top would
instead corrupt the ANSI codes this adds.
Status-code color-coding (2xx green through 5xx red) does not live in
the history/Intruder tables, despite an initial attempt to put it
there. Confirmed live: bubbles/table v1.0.0 (the newest available)
fits cell text to its column width via go-runewidth's Truncate, which
has no ANSI awareness - it counts every character of a color escape
sequence as real display width. Coloring the Status cell silently
deleted the status text from the row; the width-fitting truncation cut
into the escape sequence itself. styledStatus is used once instead, in
detailView's title, a plain string rendered whole with no width
constraint.
Verified live in tmux against a running daemon: ascending/descending
sort by status across six real entries: pretty-printed JSON confirmed
correctly colored and indented via raw ANSI capture, not just
eyeballed; the detail title's status color confirmed red for a 500
entry the same way; the request tab (never JSON) confirmed unaffected.
Diffstat (limited to 'README.md')
| -rw-r--r-- | README.md | 27 |
1 files changed, 23 insertions, 4 deletions
@@ -36,7 +36,8 @@ list of what's deliberately not implemented (and why), see text just works (`example.com`, `x-forwarded-for`, `192.168.1.1` - no quoting needed), plus structured filters: `status:404`, `status:4xx`, `status:>=400`, `source:repeater`, `flagged:true`, - column filters like `host:example.com`, and `AND`/`OR`/`NOT`. + column filters like `host:example.com`, and `AND`/`OR`/`NOT`. Sort + the loaded page by any column (`o`/`O`). - **Repeater**: edit and resend a raw request. What you type is what goes on the wire - no normalization, no auto-fixed `Content-Length`, no "helpful" reformatting. That's the point of a Repeater. Multiple @@ -247,18 +248,36 @@ below is enough to get going. | `I` | import a HAR file's entries into history | | `d` | Decoder | | `/` | search | +| `o` | cycle sort column (captured/status/size/time taken/method/host/path) | +| `O` | reverse the current sort column's direction | | `m` | match-and-replace rules | | `s` | target scope (what gets recorded) | +| `t` | client (mutual-TLS) certificates | | `q` | quit | Also mouse-driven - wheel to scroll, right-click a row for a context menu of the same actions. See [Mouse](#mouse) below. +`o` cycles which column sorts the currently loaded page (captured order +- the default, newest-first or search-relevance order - then status, +size, time taken, method, host, path); `O` reverses whichever column is +active. Client-side, on top of whatever List/Search already returned: +loading more or re-searching keeps the same sort applied. Status-code +color-coding (2xx green through 5xx red, the same convention Burp and +Caido use) isn't in the table itself - `bubbles/table`, the terminal +table widget this UI is built on, has no way to color one cell without +corrupting the whole row's layout (confirmed, not guessed: its column- +width fitting counts every character of a color code as visible text). +It's in the detail view's title instead, where that constraint doesn't +apply. + ### Detail view -`tab` switches request/response, `p` toggles pretty-printed JSON on the -response (display-only - never touches the stored or resent bytes), `c` -mark/compare (same as the history list), `r`/`i` jump straight to +`tab` switches request/response, `p` toggles pretty-printed, +syntax-highlighted JSON on the response (keys/strings/numbers/booleans +colored, matching most editors - display-only, never touches the +stored or resent bytes), `c` mark/compare (same as the history list), +`r`/`i` jump straight to Repeater/Intruder seeded from this entry, `e` exports the entry (request and response, raw bytes, plain text - type a path and press enter), `w` views captured WebSocket messages if this entry's |