srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/README.md
diff options
context:
space:
mode:
authorsrdusr <[email protected]>2026-06-09 15:46:00 +0200
committersrdusr <[email protected]>2026-06-09 15:46:00 +0200
commita2362fc08c31b23fb971279f8b160555123ad2f6 (patch)
tree6e7adf22167987f685d122f77f56b31a2ce988b2 /README.md
parent9028f8175bda63d6a85e5a2dee2b4039020317a4 (diff)
downloadmitmux-a2362fc08c31b23fb971279f8b160555123ad2f6.tar.gz
mitmux-a2362fc08c31b23fb971279f8b160555123ad2f6.zip
Body match-and-replace rules
Extends match-and-replace rules to request/response bodies, not just headers. A body rule materializes the body into memory (bounded by the same maxCaptureBytes cap as history capture) instead of streaming it straight through - the opposite of the normal path, so it's only paid when a body rule is actually configured. A body over the cap passes through byte-exact and unmodified rather than being partially rewritten. Response Content-Length is recomputed explicitly when a rule changes body length: unlike http.Request.Write, http.ResponseWriter doesn't derive it from resp.ContentLength on its own, so a stale header would otherwise corrupt response framing for the client. The history audit trail still shows the original, pre-rule bytes on both legs; only the wire traffic reflects the rewrite. Verified live against a real daemon: origin receives the rewritten request body, client receives the rewritten response body with correct Content-Length, and history keeps the unmodified bytes. Adds a Part selector (header/body) to the Rules add/edit form and table in the TUI.
Diffstat (limited to 'README.md')
-rw-r--r--README.md16
1 files changed, 9 insertions, 7 deletions
diff --git a/README.md b/README.md
index 13e9429..ea2a885 100644
--- a/README.md
+++ b/README.md
@@ -396,12 +396,15 @@ matching Burp's own behavior.
### Match-and-replace rules
Press `m` from the history view. Rules match request or response
-headers (`a` add, `enter`/`e` edit, `d` delete, `space` toggle
-enabled). Matching is literal-substring by default, or regex if the
-rule's Regex toggle is on. Rules operate on the raw header *block* as
-text, not per-value substitution, so a rule can add or remove a header
-entirely, not just rewrite an existing one. Currently headers only -
-see `PLAN.md` for why body rules are a separate, harder problem.
+headers or bodies (`a` add, `enter`/`e` edit, `d` delete, `space`
+toggle enabled, Part field to choose header vs body). Matching is
+literal-substring by default, or regex if the rule's Regex toggle is
+on. Header rules operate on the raw header *block* as text, not
+per-value substitution, so a rule can add or remove a header entirely,
+not just rewrite an existing one. Body rules run directly against the
+raw body bytes; a body larger than the capture cap is left unmodified
+rather than partially rewritten, and Content-Length is recomputed
+automatically when a body rule changes a body's length.
### Scope
@@ -515,7 +518,6 @@ messages for what was checked and how.
Deliberate scope decisions, not oversights - see `PLAN.md` for the
reasoning behind each:
-- Match-and-replace: headers only, no body rules yet
- Intruder: Sniper attack only (no battering ram / pitchfork / cluster
bomb), sequential sending, capped at 1000 requests per attack
- `mitmuxd -install-ca` prints per-OS trust-store install steps; it