diff options
| author | srdusr <[email protected]> | 2026-06-09 15:46:00 +0200 |
|---|---|---|
| committer | srdusr <[email protected]> | 2026-06-09 15:46:00 +0200 |
| commit | a2362fc08c31b23fb971279f8b160555123ad2f6 (patch) | |
| tree | 6e7adf22167987f685d122f77f56b31a2ce988b2 /README.md | |
| parent | 9028f8175bda63d6a85e5a2dee2b4039020317a4 (diff) | |
| download | mitmux-a2362fc08c31b23fb971279f8b160555123ad2f6.tar.gz mitmux-a2362fc08c31b23fb971279f8b160555123ad2f6.zip | |
Body match-and-replace rules
Extends match-and-replace rules to request/response bodies, not just
headers. A body rule materializes the body into memory (bounded by
the same maxCaptureBytes cap as history capture) instead of streaming
it straight through - the opposite of the normal path, so it's only
paid when a body rule is actually configured. A body over the cap
passes through byte-exact and unmodified rather than being partially
rewritten.
Response Content-Length is recomputed explicitly when a rule changes
body length: unlike http.Request.Write, http.ResponseWriter doesn't
derive it from resp.ContentLength on its own, so a stale header would
otherwise corrupt response framing for the client.
The history audit trail still shows the original, pre-rule bytes on
both legs; only the wire traffic reflects the rewrite. Verified live
against a real daemon: origin receives the rewritten request body,
client receives the rewritten response body with correct
Content-Length, and history keeps the unmodified bytes.
Adds a Part selector (header/body) to the Rules add/edit form and
table in the TUI.
Diffstat (limited to 'README.md')
| -rw-r--r-- | README.md | 16 |
1 files changed, 9 insertions, 7 deletions
@@ -396,12 +396,15 @@ matching Burp's own behavior. ### Match-and-replace rules Press `m` from the history view. Rules match request or response -headers (`a` add, `enter`/`e` edit, `d` delete, `space` toggle -enabled). Matching is literal-substring by default, or regex if the -rule's Regex toggle is on. Rules operate on the raw header *block* as -text, not per-value substitution, so a rule can add or remove a header -entirely, not just rewrite an existing one. Currently headers only - -see `PLAN.md` for why body rules are a separate, harder problem. +headers or bodies (`a` add, `enter`/`e` edit, `d` delete, `space` +toggle enabled, Part field to choose header vs body). Matching is +literal-substring by default, or regex if the rule's Regex toggle is +on. Header rules operate on the raw header *block* as text, not +per-value substitution, so a rule can add or remove a header entirely, +not just rewrite an existing one. Body rules run directly against the +raw body bytes; a body larger than the capture cap is left unmodified +rather than partially rewritten, and Content-Length is recomputed +automatically when a body rule changes a body's length. ### Scope @@ -515,7 +518,6 @@ messages for what was checked and how. Deliberate scope decisions, not oversights - see `PLAN.md` for the reasoning behind each: -- Match-and-replace: headers only, no body rules yet - Intruder: Sniper attack only (no battering ram / pitchfork / cluster bomb), sequential sending, capped at 1000 requests per attack - `mitmuxd -install-ca` prints per-OS trust-store install steps; it |