diff options
| author | srdusr <[email protected]> | 2026-06-09 15:46:00 +0200 |
|---|---|---|
| committer | srdusr <[email protected]> | 2026-06-09 15:46:00 +0200 |
| commit | a2362fc08c31b23fb971279f8b160555123ad2f6 (patch) | |
| tree | 6e7adf22167987f685d122f77f56b31a2ce988b2 /internal/proxy | |
| parent | 9028f8175bda63d6a85e5a2dee2b4039020317a4 (diff) | |
| download | mitmux-a2362fc08c31b23fb971279f8b160555123ad2f6.tar.gz mitmux-a2362fc08c31b23fb971279f8b160555123ad2f6.zip | |
Body match-and-replace rules
Extends match-and-replace rules to request/response bodies, not just
headers. A body rule materializes the body into memory (bounded by
the same maxCaptureBytes cap as history capture) instead of streaming
it straight through - the opposite of the normal path, so it's only
paid when a body rule is actually configured. A body over the cap
passes through byte-exact and unmodified rather than being partially
rewritten.
Response Content-Length is recomputed explicitly when a rule changes
body length: unlike http.Request.Write, http.ResponseWriter doesn't
derive it from resp.ContentLength on its own, so a stale header would
otherwise corrupt response framing for the client.
The history audit trail still shows the original, pre-rule bytes on
both legs; only the wire traffic reflects the rewrite. Verified live
against a real daemon: origin receives the rewritten request body,
client receives the rewritten response body with correct
Content-Length, and history keeps the unmodified bytes.
Adds a Part selector (header/body) to the Rules add/edit form and
table in the TUI.
Diffstat (limited to 'internal/proxy')
| -rw-r--r-- | internal/proxy/bodyrules.go | 45 | ||||
| -rw-r--r-- | internal/proxy/bodyrules_test.go | 86 | ||||
| -rw-r--r-- | internal/proxy/proxy.go | 78 |
3 files changed, 198 insertions, 11 deletions
diff --git a/internal/proxy/bodyrules.go b/internal/proxy/bodyrules.go new file mode 100644 index 0000000..128464c --- /dev/null +++ b/internal/proxy/bodyrules.go @@ -0,0 +1,45 @@ +package proxy + +import ( + "bytes" + "io" + + "mitmux/internal/rules" +) + +// applyBodyRules reads body fully (bounded by maxCaptureBytes - a body +// rule is opted into deliberately by whoever wrote it, but an unbounded +// read of a maliciously or just accidentally huge body would still be a +// memory-exhaustion vector) and, if it fits, runs bodyRules over it via +// rules.ApplyBody and returns a fresh reader over the result. +// +// If the body is larger than the cap, it's passed straight through +// completely unmodified - reconstructed from the bytes already read +// plus whatever's left on the original reader - rather than rewriting +// only part of it or dropping data. A body a rule can't safely see in +// full is better left alone than partially corrupted; applied=false +// tells the caller not to touch Content-Length, since the original +// length (whatever it was) is still exactly right. +func applyBodyRules(body io.ReadCloser, bodyRules []rules.Rule) (newBody io.ReadCloser, newLength int64, applied bool, err error) { + if body == nil { + return body, 0, false, nil + } + + limited := io.LimitReader(body, maxCaptureBytes+1) + data, err := io.ReadAll(limited) + if err != nil { + body.Close() + return nil, 0, false, err + } + + if int64(len(data)) > maxCaptureBytes { + return struct { + io.Reader + io.Closer + }{io.MultiReader(bytes.NewReader(data), body), body}, 0, false, nil + } + + body.Close() + rewritten := rules.ApplyBody(data, bodyRules) + return io.NopCloser(bytes.NewReader(rewritten)), int64(len(rewritten)), true, nil +} diff --git a/internal/proxy/bodyrules_test.go b/internal/proxy/bodyrules_test.go new file mode 100644 index 0000000..2a62855 --- /dev/null +++ b/internal/proxy/bodyrules_test.go @@ -0,0 +1,86 @@ +package proxy + +import ( + "bytes" + "io" + "strings" + "testing" + + "mitmux/internal/rules" +) + +func TestApplyBodyRulesRewrites(t *testing.T) { + body := io.NopCloser(strings.NewReader(`{"admin":false}`)) + rs := []rules.Rule{{Enabled: true, Part: "body", Match: "false", Replace: "true"}} + + newBody, newLen, applied, err := applyBodyRules(body, rs) + if err != nil { + t.Fatalf("unexpected error: %v", err) + } + if !applied { + t.Fatal("expected applied=true") + } + got, _ := io.ReadAll(newBody) + want := `{"admin":true}` + if string(got) != want { + t.Errorf("body = %q, want %q", got, want) + } + if newLen != int64(len(want)) { + t.Errorf("newLength = %d, want %d", newLen, len(want)) + } +} + +func TestApplyBodyRulesNilBody(t *testing.T) { + newBody, newLen, applied, err := applyBodyRules(nil, []rules.Rule{{Enabled: true, Part: "body"}}) + if err != nil { + t.Fatalf("unexpected error: %v", err) + } + if applied || newBody != nil || newLen != 0 { + t.Errorf("expected no-op for nil body, got body=%v len=%d applied=%v", newBody, newLen, applied) + } +} + +func TestApplyBodyRulesOversizedPassesThroughUnmodified(t *testing.T) { + // One byte over the cap: exercises the "too large to safely + // rewrite" path, which must reconstruct the ORIGINAL bytes exactly + // (not the rule applied, not truncated, not corrupted) since the + // whole point is refusing to guess at a partial rewrite. + big := bytes.Repeat([]byte("a"), maxCaptureBytes+1) + body := io.NopCloser(bytes.NewReader(big)) + rs := []rules.Rule{{Enabled: true, Part: "body", Match: "a", Replace: "b"}} + + newBody, newLen, applied, err := applyBodyRules(body, rs) + if err != nil { + t.Fatalf("unexpected error: %v", err) + } + if applied { + t.Fatal("expected applied=false for an oversized body") + } + if newLen != 0 { + t.Errorf("expected newLength=0 (caller must not touch Content-Length) for an unapplied rewrite, got %d", newLen) + } + got, err := io.ReadAll(newBody) + if err != nil { + t.Fatalf("reading reconstructed body: %v", err) + } + if !bytes.Equal(got, big) { + t.Errorf("reconstructed body does not match original: got %d bytes, want %d bytes, equal=%v", + len(got), len(big), bytes.Equal(got, big)) + } +} + +func TestApplyBodyRulesExactlyAtCapStillApplies(t *testing.T) { + // Exactly at the cap (not over it) should still be treated as + // "fits" and get the rule applied - the +1 in the LimitReader is + // what distinguishes "at the limit" from "over the limit". + body := io.NopCloser(strings.NewReader(strings.Repeat("a", maxCaptureBytes))) + rs := []rules.Rule{{Enabled: true, Part: "body", Match: "a", Replace: "b"}} + + _, _, applied, err := applyBodyRules(body, rs) + if err != nil { + t.Fatalf("unexpected error: %v", err) + } + if !applied { + t.Error("expected applied=true for a body exactly at the cap") + } +} diff --git a/internal/proxy/proxy.go b/internal/proxy/proxy.go index 523ca01..aec724a 100644 --- a/internal/proxy/proxy.go +++ b/internal/proxy/proxy.go @@ -31,6 +31,7 @@ import ( "net" "net/http" "net/url" + "strconv" "strings" "sync" "time" @@ -400,17 +401,49 @@ func (s *Server) forward(dial dialer, scheme, hostname string, w http.ResponseWr // outReq), while what actually reaches the upstream server reflects // the rules. That split is deliberate: match-and-replace is a wire // transform, not a rewrite of the audit trail. - if reqRules, err := s.enabledRules("request"); err != nil { + reqRules, err := s.enabledRules("request") + if err != nil { log.Printf("load request rules: %v", err) - } else if len(reqRules) > 0 { + reqRules = nil + } + if len(reqRules) > 0 { outReq.Header = rules.ApplyHeaders(outReq.Header, reqRules) } - // Only needed when the client leg isn't tee-captured (HTTP/2): tee - // the body as it streams through so the reconstructed capture isn't - // missing it. + // A body rule needs the body materialized in memory to rewrite it - + // the exact opposite of the normal streamed-straight-through path, + // which is what makes exact capture of an arbitrarily large body + // possible without ever buffering it. Only paid when a body rule is + // actually configured and enabled; everyone else keeps streaming. var reqBodyCap *cappedTee - if clientTee == nil && outReq.Body != nil { + if rules.HasBodyRules(reqRules) && outReq.Body != nil { + if clientTee == nil { + // H2: nothing has captured this body's original bytes yet - + // wrap it first so draining it below (to apply the rule) + // captures them as a side effect, same as the unconditional + // wrap further down does when no body rule is in play. + reqBodyCap = newCappedTee(outReq.Body) + outReq.Body = io.NopCloser(reqBodyCap) + } + // H1: clientTee already captures every byte read off the client + // connection regardless of who's doing the reading, so draining + // outReq.Body here (which for H1 is the same underlying reader + // r.Body was, per Clone's documented behavior of not deep- + // copying Body) is captured exactly as if roundTripH1 had read + // it directly during the actual upstream write. + newBody, newLen, applied, bodyErr := applyBodyRules(outReq.Body, reqRules) + if bodyErr != nil { + log.Printf("apply request body rules: %v", bodyErr) + } else { + outReq.Body = newBody + if applied { + outReq.ContentLength = newLen + } + } + } + // Only needed when the client leg isn't tee-captured (HTTP/2) and a + // body rule hasn't already wrapped/captured it above. + if clientTee == nil && outReq.Body != nil && reqBodyCap == nil { reqBodyCap = newCappedTee(outReq.Body) outReq.Body = io.NopCloser(reqBodyCap) } @@ -435,7 +468,6 @@ func (s *Server) forward(dial dialer, scheme, hostname string, w http.ResponseWr var resp *http.Response var upstreamTee *teeConn - var err error if negotiated == http2.NextProtoTLS { resp, err = roundTripH2(conn, outReq) } else { @@ -456,6 +488,12 @@ func (s *Server) forward(dial dialer, scheme, hostname string, w http.ResponseWr } defer resp.Body.Close() + respRules, err := s.enabledRules("response") + if err != nil { + log.Printf("load response rules: %v", err) + respRules = nil + } + var respBodyCap *cappedTee if upstreamTee == nil { respBodyCap = newCappedTee(resp.Body) @@ -466,13 +504,31 @@ func (s *Server) forward(dial dialer, scheme, hostname string, w http.ResponseWr // the origin server actually sent (captured below, from upstreamTee // or respBodyCap, both already wired to resp.Body independent of // resp.Header), while the client actually receives the rule-modified - // headers. - if respRules, err := s.enabledRules("response"); err != nil { - log.Printf("load response rules: %v", err) - } else if len(respRules) > 0 { + // headers/body. + if len(respRules) > 0 { resp.Header = rules.ApplyHeaders(resp.Header, respRules) } + if rules.HasBodyRules(respRules) && resp.Body != nil { + newBody, newLen, applied, bodyErr := applyBodyRules(resp.Body, respRules) + if bodyErr != nil { + log.Printf("apply response body rules: %v", bodyErr) + } else { + resp.Body = newBody + if applied { + // Unlike http.Request.Write (which derives the wire + // Content-Length from req.ContentLength regardless of any + // stale header), http.ResponseWriter does not: the loop + // below just forwards whatever's in resp.Header verbatim. + // A body rule that changes length would otherwise leave a + // stale Content-Length on the wire and corrupt response + // framing for the client. + resp.ContentLength = newLen + resp.Header.Set("Content-Length", strconv.FormatInt(newLen, 10)) + } + } + } + stripHopByHop(resp.Header) for k, vv := range resp.Header { for _, v := range vv { |