srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/internal/rules
diff options
context:
space:
mode:
authorsrdusr <[email protected]>2026-08-25 15:58:00 +0200
committersrdusr <[email protected]>2026-08-25 15:58:00 +0200
commit9e94bcbc939afd38b45f9ef42e1b1666fafd8d45 (patch)
tree88a36226ee332c74e2dba98a9568a3a09ad074a8 /internal/rules
parentdde73a349a68f942a5bd89b27ac980d7973148e0 (diff)
downloadmitmux-9e94bcbc939afd38b45f9ef42e1b1666fafd8d45.tar.gz
mitmux-9e94bcbc939afd38b45f9ef42e1b1666fafd8d45.zip
Wire-format JSON tag consistency fix, and the first real plugin
Writing PLUGINS.md as an authoritative external spec surfaced a real, pre-existing bug: store.Summary/Entry/EntryTag/WSMessage, rules.Rule, scope.Rule, and clientcert.Cert had no JSON struct tags at all, so Go's default marshaling serialized them PascalCase ("ID", "StartedAt") while the rest of the protocol (EntryDetail's own fields, every Request/Response wrapper field) uses snake_case. Confirmed live against a real daemon before touching anything: a raw socket "list" request came back with "ID"/"StartedAt"/"StatusCode", exactly the mismatch suspected. Nothing outside this repo's own Go code consumes this wire format yet, so this was a free, purely additive fix rather than something to work around - every affected struct now tags snake_case consistently. plugins/authcheck is the first real plugin: an Autorize-style authorization checker. For every proxied request carrying an Authorization or Cookie header, resends it with that header stripped and compares status classes - a resend that still succeeds where the original did too is a likely missing-function-level-access-control bug, tagged authcheck:bypass with structured detail. Deliberately speaks the wire protocol directly (its own local request/response/ summary/entryDetail structs mirroring the real ones field-for-field, not imported from internal/ipc) rather than taking the shortcut a Go plugin could - proof the documented protocol is actually sufficient on its own, since that's all a non-Go plugin author has to work with. Verified live end to end: a real daemon, a real Python origin with one endpoint that looks like it enforces auth but doesn't (vulnerable by design) and one that actually does (the control case) - the broken endpoint was correctly tagged, the secure one correctly left alone, no false positive, confirmed both via the stored tag data directly and visually in the TUI (tmux, real keystrokes): the Tags column badge, T's tag list, and the tag detail view's JSON-colorized data (ANSI-verified, not eyeballed) all showing the plugin's actual findings.
Diffstat (limited to 'internal/rules')
-rw-r--r--internal/rules/rules.go18
1 files changed, 9 insertions, 9 deletions
diff --git a/internal/rules/rules.go b/internal/rules/rules.go
index e0547db..76d2ce7 100644
--- a/internal/rules/rules.go
+++ b/internal/rules/rules.go
@@ -14,17 +14,17 @@ import (
// Rule is one match-and-replace rule.
type Rule struct {
- ID int64
- Enabled bool
- Name string
- Scope string // "request" or "response"
- Part string // "header" or "body"
- Match string
- Replace string
- IsRegex bool
+ ID int64 `json:"id"`
+ Enabled bool `json:"enabled"`
+ Name string `json:"name"`
+ Scope string `json:"scope"` // "request" or "response"
+ Part string `json:"part"` // "header" or "body"
+ Match string `json:"match"`
+ Replace string `json:"replace"`
+ IsRegex bool `json:"is_regex"`
// Position orders rule application (ascending) when several rules
// could touch the same text.
- Position int
+ Position int `json:"position"`
}
// ApplyHeaders rewrites h in place by serializing it to a raw