srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/internal/proxy/proxy.go
diff options
context:
space:
mode:
authorsrdusr <[email protected]>2026-05-15 19:48:00 +0200
committersrdusr <[email protected]>2026-05-15 19:48:00 +0200
commitdd1621c0077e079e0693f16fe83f17d50338216e (patch)
tree411a06d723a16aff1077d5d3e724680436aac85a /internal/proxy/proxy.go
parentd7d50ae9902d69b2e52d446684b5ab01a5ecab1e (diff)
downloadmitmux-dd1621c0077e079e0693f16fe83f17d50338216e.tar.gz
mitmux-dd1621c0077e079e0693f16fe83f17d50338216e.zip
Stop mislabeling truncated captures as "exact"
internal/proxy/tee.go's teeConn silently drops bytes past maxCaptureBytes (10 MiB) but callers unconditionally marked the result "exact" anyway. Confirmed live: proxying a 15 MiB response worked correctly end-to-end (the client got the full, real 15 MiB - proxying itself is unbounded, only storage is capped), but the stored history entry was exactly 10485760 bytes with response_exact=1 still set. For a tool whose core value proposition is "raw bytes are the source of truth," a silently truncated capture presented as complete could hide the very evidence a smuggling or parser-differential investigation is looking for in the tail of a large body - and give false confidence that it isn't there. teeConn.Take() now returns (data, truncated) instead of just data; truncated is true whenever a Read had to drop bytes because the buffer was already at cap. Every caller (proxy.go's forward() on both the request and response side, repeat.go's sendRaw for Repeater/Intruder) now folds truncated into exact - a truncated capture is never marked exact - and additionally threads a distinct RequestTruncated/ ResponseTruncated bool through store.Entry, ipc.EntryDetail, and the TUI, since "truncated" and "reconstructed" (HTTP/2, which never had wire-exact bytes to begin with) are different situations worth telling apart: a truncated capture is still real wire bytes, just incomplete, not a synthesized reconstruction. The detail/repeater views now show "truncated (hit capture size limit)" specifically rather than lumping it in with "reconstructed", which would have implied more transformation happened than actually did. Schema: history gains request_truncated/response_truncated columns via the same ALTER-TABLE-and-ignore-duplicate-column pattern already used for source/flagged, so existing databases upgrade in place. Verified live: a target server returning a 15 MiB body (over the 10 MiB cap) proxied through cleanly - full body reached the client - while the stored entry shows length=10485760, response_exact=0, response_truncated=1 (previously would have shown response_exact=1); the TUI's Detail view correctly displays "Response (10485760 bytes, truncated (hit capture size limit))" instead of "exact". go build/vet/gofmt/test/mod tidy all clean.
Diffstat (limited to 'internal/proxy/proxy.go')
-rw-r--r--internal/proxy/proxy.go43
1 files changed, 23 insertions, 20 deletions
diff --git a/internal/proxy/proxy.go b/internal/proxy/proxy.go
index 82328db..08b8551 100644
--- a/internal/proxy/proxy.go
+++ b/internal/proxy/proxy.go
@@ -383,8 +383,8 @@ func (s *Server) forward(dial dialer, scheme, hostname string, w http.ResponseWr
started := time.Now()
conn, negotiated, dialErr := dial(r.Context())
if dialErr != nil {
- reqRaw, reqExact := captureRequest(r, clientTee, reqBodyCap)
- s.record(started, time.Since(started), scheme, hostname, r, reqRaw, reqExact, nil, false, 0, dialErr.Error())
+ reqRaw, reqExact, reqTrunc := captureRequest(r, clientTee, reqBodyCap)
+ s.record(started, time.Since(started), scheme, hostname, r, reqRaw, reqExact, reqTrunc, nil, false, false, 0, dialErr.Error())
http.Error(w, dialErr.Error(), http.StatusBadGateway)
return
}
@@ -412,10 +412,10 @@ func (s *Server) forward(dial dialer, scheme, hostname string, w http.ResponseWr
}
duration := time.Since(started)
- reqRaw, reqExact := captureRequest(r, clientTee, reqBodyCap)
+ reqRaw, reqExact, reqTrunc := captureRequest(r, clientTee, reqBodyCap)
if err != nil {
- s.record(started, duration, scheme, hostname, r, reqRaw, reqExact, nil, false, 0, err.Error())
+ s.record(started, duration, scheme, hostname, r, reqRaw, reqExact, reqTrunc, nil, false, false, 0, err.Error())
http.Error(w, err.Error(), http.StatusBadGateway)
return
}
@@ -448,14 +448,15 @@ func (s *Server) forward(dial dialer, scheme, hostname string, w http.ResponseWr
io.Copy(w, resp.Body)
var respRaw []byte
- var respExact bool
+ var respExact, respTrunc bool
if upstreamTee != nil {
- respRaw, respExact = upstreamTee.Take(), true
+ respRaw, respTrunc = upstreamTee.Take()
+ respExact = !respTrunc
} else {
respRaw, respExact = captureResponse(resp, respBodyCap)
}
- s.record(started, duration, scheme, hostname, r, reqRaw, reqExact, respRaw, respExact, resp.StatusCode, "")
+ s.record(started, duration, scheme, hostname, r, reqRaw, reqExact, reqTrunc, respRaw, respExact, respTrunc, resp.StatusCode, "")
}
// enabledRules fetches the current enabled match-and-replace rules for
@@ -471,24 +472,26 @@ func (s *Server) enabledRules(scope string) ([]rules.Rule, error) {
// record stores one history entry and notifies OnEntry.
func (s *Server) record(started time.Time, duration time.Duration, scheme, host string, r *http.Request,
- reqRaw []byte, reqExact bool, respRaw []byte, respExact bool, status int, errMsg string) {
+ reqRaw []byte, reqExact, reqTruncated bool, respRaw []byte, respExact, respTruncated bool, status int, errMsg string) {
if s.store == nil {
return
}
e := &store.Entry{
- StartedAt: started,
- Duration: duration,
- Method: r.Method,
- Scheme: scheme,
- Host: host,
- Path: r.URL.Path,
- StatusCode: status,
- RequestRaw: reqRaw,
- ResponseRaw: respRaw,
- RequestExact: reqExact,
- ResponseExact: respExact,
- Error: errMsg,
+ StartedAt: started,
+ Duration: duration,
+ Method: r.Method,
+ Scheme: scheme,
+ Host: host,
+ Path: r.URL.Path,
+ StatusCode: status,
+ RequestRaw: reqRaw,
+ ResponseRaw: respRaw,
+ RequestExact: reqExact,
+ ResponseExact: respExact,
+ RequestTruncated: reqTruncated,
+ ResponseTruncated: respTruncated,
+ Error: errMsg,
}
id, err := s.store.Insert(e)
if err != nil {