srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/internal/proxy
diff options
context:
space:
mode:
authorsrdusr <[email protected]>2026-06-09 15:46:00 +0200
committersrdusr <[email protected]>2026-06-09 15:46:00 +0200
commita2362fc08c31b23fb971279f8b160555123ad2f6 (patch)
tree6e7adf22167987f685d122f77f56b31a2ce988b2 /internal/proxy
parent9028f8175bda63d6a85e5a2dee2b4039020317a4 (diff)
downloadmitmux-a2362fc08c31b23fb971279f8b160555123ad2f6.tar.gz
mitmux-a2362fc08c31b23fb971279f8b160555123ad2f6.zip
Body match-and-replace rules
Extends match-and-replace rules to request/response bodies, not just headers. A body rule materializes the body into memory (bounded by the same maxCaptureBytes cap as history capture) instead of streaming it straight through - the opposite of the normal path, so it's only paid when a body rule is actually configured. A body over the cap passes through byte-exact and unmodified rather than being partially rewritten. Response Content-Length is recomputed explicitly when a rule changes body length: unlike http.Request.Write, http.ResponseWriter doesn't derive it from resp.ContentLength on its own, so a stale header would otherwise corrupt response framing for the client. The history audit trail still shows the original, pre-rule bytes on both legs; only the wire traffic reflects the rewrite. Verified live against a real daemon: origin receives the rewritten request body, client receives the rewritten response body with correct Content-Length, and history keeps the unmodified bytes. Adds a Part selector (header/body) to the Rules add/edit form and table in the TUI.
Diffstat (limited to 'internal/proxy')
-rw-r--r--internal/proxy/bodyrules.go45
-rw-r--r--internal/proxy/bodyrules_test.go86
-rw-r--r--internal/proxy/proxy.go78
3 files changed, 198 insertions, 11 deletions
diff --git a/internal/proxy/bodyrules.go b/internal/proxy/bodyrules.go
new file mode 100644
index 0000000..128464c
--- /dev/null
+++ b/internal/proxy/bodyrules.go
@@ -0,0 +1,45 @@
+package proxy
+
+import (
+ "bytes"
+ "io"
+
+ "mitmux/internal/rules"
+)
+
+// applyBodyRules reads body fully (bounded by maxCaptureBytes - a body
+// rule is opted into deliberately by whoever wrote it, but an unbounded
+// read of a maliciously or just accidentally huge body would still be a
+// memory-exhaustion vector) and, if it fits, runs bodyRules over it via
+// rules.ApplyBody and returns a fresh reader over the result.
+//
+// If the body is larger than the cap, it's passed straight through
+// completely unmodified - reconstructed from the bytes already read
+// plus whatever's left on the original reader - rather than rewriting
+// only part of it or dropping data. A body a rule can't safely see in
+// full is better left alone than partially corrupted; applied=false
+// tells the caller not to touch Content-Length, since the original
+// length (whatever it was) is still exactly right.
+func applyBodyRules(body io.ReadCloser, bodyRules []rules.Rule) (newBody io.ReadCloser, newLength int64, applied bool, err error) {
+ if body == nil {
+ return body, 0, false, nil
+ }
+
+ limited := io.LimitReader(body, maxCaptureBytes+1)
+ data, err := io.ReadAll(limited)
+ if err != nil {
+ body.Close()
+ return nil, 0, false, err
+ }
+
+ if int64(len(data)) > maxCaptureBytes {
+ return struct {
+ io.Reader
+ io.Closer
+ }{io.MultiReader(bytes.NewReader(data), body), body}, 0, false, nil
+ }
+
+ body.Close()
+ rewritten := rules.ApplyBody(data, bodyRules)
+ return io.NopCloser(bytes.NewReader(rewritten)), int64(len(rewritten)), true, nil
+}
diff --git a/internal/proxy/bodyrules_test.go b/internal/proxy/bodyrules_test.go
new file mode 100644
index 0000000..2a62855
--- /dev/null
+++ b/internal/proxy/bodyrules_test.go
@@ -0,0 +1,86 @@
+package proxy
+
+import (
+ "bytes"
+ "io"
+ "strings"
+ "testing"
+
+ "mitmux/internal/rules"
+)
+
+func TestApplyBodyRulesRewrites(t *testing.T) {
+ body := io.NopCloser(strings.NewReader(`{"admin":false}`))
+ rs := []rules.Rule{{Enabled: true, Part: "body", Match: "false", Replace: "true"}}
+
+ newBody, newLen, applied, err := applyBodyRules(body, rs)
+ if err != nil {
+ t.Fatalf("unexpected error: %v", err)
+ }
+ if !applied {
+ t.Fatal("expected applied=true")
+ }
+ got, _ := io.ReadAll(newBody)
+ want := `{"admin":true}`
+ if string(got) != want {
+ t.Errorf("body = %q, want %q", got, want)
+ }
+ if newLen != int64(len(want)) {
+ t.Errorf("newLength = %d, want %d", newLen, len(want))
+ }
+}
+
+func TestApplyBodyRulesNilBody(t *testing.T) {
+ newBody, newLen, applied, err := applyBodyRules(nil, []rules.Rule{{Enabled: true, Part: "body"}})
+ if err != nil {
+ t.Fatalf("unexpected error: %v", err)
+ }
+ if applied || newBody != nil || newLen != 0 {
+ t.Errorf("expected no-op for nil body, got body=%v len=%d applied=%v", newBody, newLen, applied)
+ }
+}
+
+func TestApplyBodyRulesOversizedPassesThroughUnmodified(t *testing.T) {
+ // One byte over the cap: exercises the "too large to safely
+ // rewrite" path, which must reconstruct the ORIGINAL bytes exactly
+ // (not the rule applied, not truncated, not corrupted) since the
+ // whole point is refusing to guess at a partial rewrite.
+ big := bytes.Repeat([]byte("a"), maxCaptureBytes+1)
+ body := io.NopCloser(bytes.NewReader(big))
+ rs := []rules.Rule{{Enabled: true, Part: "body", Match: "a", Replace: "b"}}
+
+ newBody, newLen, applied, err := applyBodyRules(body, rs)
+ if err != nil {
+ t.Fatalf("unexpected error: %v", err)
+ }
+ if applied {
+ t.Fatal("expected applied=false for an oversized body")
+ }
+ if newLen != 0 {
+ t.Errorf("expected newLength=0 (caller must not touch Content-Length) for an unapplied rewrite, got %d", newLen)
+ }
+ got, err := io.ReadAll(newBody)
+ if err != nil {
+ t.Fatalf("reading reconstructed body: %v", err)
+ }
+ if !bytes.Equal(got, big) {
+ t.Errorf("reconstructed body does not match original: got %d bytes, want %d bytes, equal=%v",
+ len(got), len(big), bytes.Equal(got, big))
+ }
+}
+
+func TestApplyBodyRulesExactlyAtCapStillApplies(t *testing.T) {
+ // Exactly at the cap (not over it) should still be treated as
+ // "fits" and get the rule applied - the +1 in the LimitReader is
+ // what distinguishes "at the limit" from "over the limit".
+ body := io.NopCloser(strings.NewReader(strings.Repeat("a", maxCaptureBytes)))
+ rs := []rules.Rule{{Enabled: true, Part: "body", Match: "a", Replace: "b"}}
+
+ _, _, applied, err := applyBodyRules(body, rs)
+ if err != nil {
+ t.Fatalf("unexpected error: %v", err)
+ }
+ if !applied {
+ t.Error("expected applied=true for a body exactly at the cap")
+ }
+}
diff --git a/internal/proxy/proxy.go b/internal/proxy/proxy.go
index 523ca01..aec724a 100644
--- a/internal/proxy/proxy.go
+++ b/internal/proxy/proxy.go
@@ -31,6 +31,7 @@ import (
"net"
"net/http"
"net/url"
+ "strconv"
"strings"
"sync"
"time"
@@ -400,17 +401,49 @@ func (s *Server) forward(dial dialer, scheme, hostname string, w http.ResponseWr
// outReq), while what actually reaches the upstream server reflects
// the rules. That split is deliberate: match-and-replace is a wire
// transform, not a rewrite of the audit trail.
- if reqRules, err := s.enabledRules("request"); err != nil {
+ reqRules, err := s.enabledRules("request")
+ if err != nil {
log.Printf("load request rules: %v", err)
- } else if len(reqRules) > 0 {
+ reqRules = nil
+ }
+ if len(reqRules) > 0 {
outReq.Header = rules.ApplyHeaders(outReq.Header, reqRules)
}
- // Only needed when the client leg isn't tee-captured (HTTP/2): tee
- // the body as it streams through so the reconstructed capture isn't
- // missing it.
+ // A body rule needs the body materialized in memory to rewrite it -
+ // the exact opposite of the normal streamed-straight-through path,
+ // which is what makes exact capture of an arbitrarily large body
+ // possible without ever buffering it. Only paid when a body rule is
+ // actually configured and enabled; everyone else keeps streaming.
var reqBodyCap *cappedTee
- if clientTee == nil && outReq.Body != nil {
+ if rules.HasBodyRules(reqRules) && outReq.Body != nil {
+ if clientTee == nil {
+ // H2: nothing has captured this body's original bytes yet -
+ // wrap it first so draining it below (to apply the rule)
+ // captures them as a side effect, same as the unconditional
+ // wrap further down does when no body rule is in play.
+ reqBodyCap = newCappedTee(outReq.Body)
+ outReq.Body = io.NopCloser(reqBodyCap)
+ }
+ // H1: clientTee already captures every byte read off the client
+ // connection regardless of who's doing the reading, so draining
+ // outReq.Body here (which for H1 is the same underlying reader
+ // r.Body was, per Clone's documented behavior of not deep-
+ // copying Body) is captured exactly as if roundTripH1 had read
+ // it directly during the actual upstream write.
+ newBody, newLen, applied, bodyErr := applyBodyRules(outReq.Body, reqRules)
+ if bodyErr != nil {
+ log.Printf("apply request body rules: %v", bodyErr)
+ } else {
+ outReq.Body = newBody
+ if applied {
+ outReq.ContentLength = newLen
+ }
+ }
+ }
+ // Only needed when the client leg isn't tee-captured (HTTP/2) and a
+ // body rule hasn't already wrapped/captured it above.
+ if clientTee == nil && outReq.Body != nil && reqBodyCap == nil {
reqBodyCap = newCappedTee(outReq.Body)
outReq.Body = io.NopCloser(reqBodyCap)
}
@@ -435,7 +468,6 @@ func (s *Server) forward(dial dialer, scheme, hostname string, w http.ResponseWr
var resp *http.Response
var upstreamTee *teeConn
- var err error
if negotiated == http2.NextProtoTLS {
resp, err = roundTripH2(conn, outReq)
} else {
@@ -456,6 +488,12 @@ func (s *Server) forward(dial dialer, scheme, hostname string, w http.ResponseWr
}
defer resp.Body.Close()
+ respRules, err := s.enabledRules("response")
+ if err != nil {
+ log.Printf("load response rules: %v", err)
+ respRules = nil
+ }
+
var respBodyCap *cappedTee
if upstreamTee == nil {
respBodyCap = newCappedTee(resp.Body)
@@ -466,13 +504,31 @@ func (s *Server) forward(dial dialer, scheme, hostname string, w http.ResponseWr
// the origin server actually sent (captured below, from upstreamTee
// or respBodyCap, both already wired to resp.Body independent of
// resp.Header), while the client actually receives the rule-modified
- // headers.
- if respRules, err := s.enabledRules("response"); err != nil {
- log.Printf("load response rules: %v", err)
- } else if len(respRules) > 0 {
+ // headers/body.
+ if len(respRules) > 0 {
resp.Header = rules.ApplyHeaders(resp.Header, respRules)
}
+ if rules.HasBodyRules(respRules) && resp.Body != nil {
+ newBody, newLen, applied, bodyErr := applyBodyRules(resp.Body, respRules)
+ if bodyErr != nil {
+ log.Printf("apply response body rules: %v", bodyErr)
+ } else {
+ resp.Body = newBody
+ if applied {
+ // Unlike http.Request.Write (which derives the wire
+ // Content-Length from req.ContentLength regardless of any
+ // stale header), http.ResponseWriter does not: the loop
+ // below just forwards whatever's in resp.Header verbatim.
+ // A body rule that changes length would otherwise leave a
+ // stale Content-Length on the wire and corrupt response
+ // framing for the client.
+ resp.ContentLength = newLen
+ resp.Header.Set("Content-Length", strconv.FormatInt(newLen, 10))
+ }
+ }
+ }
+
stripHopByHop(resp.Header)
for k, vv := range resp.Header {
for _, v := range vv {