srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/README.md
diff options
context:
space:
mode:
authorsrdusr <[email protected]>2026-05-22 21:47:00 +0200
committersrdusr <[email protected]>2026-05-22 21:47:00 +0200
commitd522b1177a9e1fdd04888121975f2b3509d19564 (patch)
tree8f4a8acb9ce73ba7d656cdb5c05c26002e3a028c /README.md
parent51811b67018515366bd56f3c3b21aed11d906db2 (diff)
downloadmitmux-d522b1177a9e1fdd04888121975f2b3509d19564.tar.gz
mitmux-d522b1177a9e1fdd04888121975f2b3509d19564.zip
CSV export and copy-as-curl (multiple export formats, like Burp)
Both extend the existing export system by dispatching on the file extension the user types, rather than adding a separate format- selection control - consistent with how any "save as" dialog already works, and requires no new UI beyond what export already has. Bulk export ('E' from the history list): .har (existing default) or .csv. CSV is a summary table (id/method/host/path/status/sizes/timing/ flag/source) built directly from the already-loaded Summary rows - deliberately lighter and faster than HAR, which needs a per-entry fetch from the daemon to get raw bytes. This mirrors Burp's own "export as CSV" being a listing for a report/spreadsheet, not a full-fidelity capture format - HAR already covers that need. Single-entry export ('e' from Detail view): .txt (existing default, unchanged) or .sh/.curl - the request re-serialized as a runnable curl command line (Burp/DevTools' "copy as curl"), for handing to someone else or re-running standalone without mitmux. Every value is shell- quoted (single-quote wrapping with '\'' escaping for embedded quotes) - a captured or edited request is exactly the kind of content that might contain shell metacharacters, so naive string concatenation would risk producing a command that does something other than what it appears to when pasted into a shell. Verified by actually executing a generated command against the real target and confirming the response matched the original request. CSV export needed one thing HAR didn't: a guard against CSV/formula injection. Method, host, path, and error all ultimately trace back to a request line or Host header - content this tool exists specifically to inspect from potentially hostile traffic - and a field starting with =, +, -, @, tab, or CR is a formula to Excel/LibreOffice/Sheets when the exported file is later opened, which can call out to other cells, external data, or worse depending on the app and its settings. csvSafe prefixes any such field with a single quote before writing - the standard mitigation per OWASP's own CSV injection guidance - so every affected spreadsheet application treats it as literal text instead. This is the same class of bug as the terminal-injection fix from the earlier robustness audit, just for a different output format: captured content controlling whatever later processes it, rather than the terminal that renders it. cmd/mitmux/csv.go: csvFromSummaries + csvSafe, unit tested including the formula-injection neutralization specifically. cmd/mitmux/export.go: curlCommand + shellQuote, plus singleEntryFormat/bulkExportFormat extension-dispatch helpers, all unit tested (curl generation, malformed- request handling, shell-quote escaping of embedded quotes). go build/vet/gofmt/test/mod tidy all clean.
Diffstat (limited to 'README.md')
-rw-r--r--README.md45
1 files changed, 31 insertions, 14 deletions
diff --git a/README.md b/README.md
index de8274e..7058180 100644
--- a/README.md
+++ b/README.md
@@ -158,7 +158,7 @@ below is enough to get going.
| `c` | mark for comparison - press `c` on another entry to diff |
| `x` | delete the selected entry (asks `y`/`n` to confirm) |
| `X` | clear ALL history, not just the current search filter (asks `y`/`n` to confirm) |
-| `E` | export the current view (respects an active search filter) as a HAR file |
+| `E` | export the current view (respects an active search filter) - `.har` or `.csv` |
| `d` | Decoder |
| `/` | search |
| `m` | match-and-replace rules |
@@ -196,20 +196,37 @@ only - not chained/pipelined the way Burp's Decoder supports.
### Export
Two independent export paths, both a modal path-prompt (`enter` writes
-and confirms, `esc` cancels):
-
-- `e` from Detail view exports the single selected entry - request and
- response raw bytes, plain text, exactly what Detail view already
- shows. Each side is annotated when it isn't wire-exact (truncated or
- reconstructed), matching Detail view's own labels.
+and confirms, `esc` cancels). Format is picked by the extension you
+type, the same convention any "save as" dialog uses - no separate
+format-selection control:
+
+- `e` from Detail view exports the single selected entry.
+ - `.txt` (default) - request and response raw bytes, plain text,
+ exactly what Detail view already shows. Each side is annotated when
+ it isn't wire-exact (truncated or reconstructed), matching Detail
+ view's own labels.
+ - `.sh` / `.curl` - the request as a runnable `curl` command line
+ (Burp/DevTools' own "copy as curl"), for handing to someone else or
+ re-running standalone without mitmux. Every value is shell-quoted
+ (a captured or edited request can contain arbitrary bytes).
- `E` from the history list exports the current view - the visible,
- filtered set if a search is active, everything otherwise - as one
- [HAR](https://en.wikipedia.org/wiki/HAR_(file_format)) file, for
- importing into Chrome/Firefox DevTools, Burp, Postman, or anything
- else that reads HAR 1.2. A binary body (an image, say) is base64-
- encoded in the HAR rather than corrupted as text. An entry that fails
- to fetch or parse is skipped rather than aborting the whole export;
- the status line reports how many, if any.
+ filtered set if a search is active, everything otherwise.
+ - `.har` (default) - one
+ [HAR](https://en.wikipedia.org/wiki/HAR_(file_format)) 1.2 file, for
+ importing into Chrome/Firefox DevTools, Burp, Postman, or anything
+ else that reads HAR. A binary body (an image, say) is base64-
+ encoded rather than corrupted as text. An entry that fails to fetch
+ or parse is skipped rather than aborting the whole export; the
+ status line reports how many, if any.
+ - `.csv` - a summary table (id, method, host, path, status, sizes,
+ timing, flag, source) for a report or spreadsheet - lighter and
+ faster than HAR since it needs no per-entry fetch from the daemon.
+ Any field that could be interpreted as a spreadsheet formula (starts
+ with `=`, `+`, `-`, `@`, tab, or CR - method/host/path/error all
+ ultimately trace back to a request line or Host header, exactly the
+ kind of content this tool exists to inspect from hostile traffic)
+ is neutralized with a leading quote before writing, the standard
+ CSV-injection mitigation.
There's no import yet (see `PLAN.md`).