srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/internal/store
diff options
context:
space:
mode:
authorsrdusr <[email protected]>2026-06-30 14:52:00 +0200
committersrdusr <[email protected]>2026-06-30 14:52:00 +0200
commit384573a2dc5e3b8e2a7bdfe2ce949f2c52ba2c52 (patch)
tree13bfe97b1f5bcf90e3fad33d90b522b29f3e439d /internal/store
parent2ade8c807584bff0b60d6b6f278dbde29b13a5ff (diff)
downloadmitmux-384573a2dc5e3b8e2a7bdfe2ce949f2c52ba2c52.tar.gz
mitmux-384573a2dc5e3b8e2a7bdfe2ce949f2c52ba2c52.zip
WebSocket interception
The last "known limitation": a ws://wss:// connection stops being one-shot request/response the instant its 101 Switching Protocols lands, and forward()'s normal write-response-then-record flow has no way to represent that. Scoped to HTTP/1.1 client legs (HTTP/2 can't be hijacked for raw post-response access the way HTTP/1.1 can, and browsers open a dedicated HTTP/1.1 connection for WebSocket regardless of the surrounding page's protocol, so this isn't a real-world gap). internal/proxy/websocket.go decodes each RFC 6455 frame's opcode and payload for capture while relaying the exact same raw bytes it read unmodified - this is capture, not tampering, matching the rest of the codebase's raw-bytes-as-source-of-truth stance. One row per frame, not per reassembled message (fragmentation is rare in real-world WebSocket traffic; not worth buffering an unbounded number of pending fragments to handle it). forward() branches on a matching 101 into handleWebSocketUpgrade, which hijacks the client connection, relays the handshake response raw, records the upgrade request/response to history normally, then relays frames bidirectionally into a new ws_messages table - reachable from the TUI's detail view via `w`. Found and fixed two real bugs by actually driving a WebSocket connection through a running daemon, not by reading the code: stripHopByHop was deleting Connection/Upgrade from every outgoing request (correct for an ordinary request per RFC 7230, catastrophic for one asking to upgrade - every WebSocket attempt silently became a 426); and the relay tore the whole connection down the instant either side saw a close frame, before the peer's own close-frame reply could be relayed back, producing an abrupt EOF instead of a clean close. Verified live end to end on both paths a real client uses: ws:// (plain HTTP forward-proxying) against a Python websockets echo server, and wss:// (CONNECT-tunneled, TLS-intercepted) against the same server behind TLS - text, binary, and extended-length frames, plus a full close handshake with both directions' close frames present, confirmed via the actual bytes captured in ws_messages.
Diffstat (limited to 'internal/store')
-rw-r--r--internal/store/store.go61
1 files changed, 61 insertions, 0 deletions
diff --git a/internal/store/store.go b/internal/store/store.go
index 0e57c3c..e0f27d1 100644
--- a/internal/store/store.go
+++ b/internal/store/store.go
@@ -74,6 +74,17 @@ CREATE TABLE IF NOT EXISTS client_certs (
cert_pem BLOB NOT NULL,
key_pem BLOB NOT NULL
);
+
+CREATE TABLE IF NOT EXISTS ws_messages (
+ id INTEGER PRIMARY KEY AUTOINCREMENT,
+ entry_id INTEGER NOT NULL,
+ started_at INTEGER NOT NULL,
+ direction TEXT NOT NULL,
+ opcode INTEGER NOT NULL,
+ payload BLOB NOT NULL
+);
+
+CREATE INDEX IF NOT EXISTS ws_messages_entry_id ON ws_messages(entry_id);
`
// Store is a handle to the history database. Safe for concurrent use.
@@ -683,6 +694,56 @@ func (s *Store) DeleteClientCert(id int64) error {
return nil
}
+// WSMessage is one captured WebSocket frame, tagged to the history entry
+// of the upgrade request/response that started its connection - see
+// internal/proxy/websocket.go for why it's one row per frame rather than
+// per reassembled logical message.
+type WSMessage struct {
+ ID int64
+ EntryID int64
+ StartedAt time.Time
+ Direction string // "client_to_server" or "server_to_client"
+ Opcode int // RFC 6455 opcode: 1 text, 2 binary, 8 close, 9 ping, 10 pong
+ Payload []byte
+}
+
+// AddWSMessage stores one captured frame and returns its assigned ID.
+func (s *Store) AddWSMessage(m WSMessage) (int64, error) {
+ res, err := s.db.Exec(
+ `INSERT INTO ws_messages (entry_id, started_at, direction, opcode, payload) VALUES (?, ?, ?, ?, ?)`,
+ m.EntryID, m.StartedAt.UnixMilli(), m.Direction, m.Opcode, m.Payload,
+ )
+ if err != nil {
+ return 0, fmt.Errorf("add ws message: %w", err)
+ }
+ return res.LastInsertId()
+}
+
+// ListWSMessages returns every frame captured for entryID's WebSocket
+// connection, in the order they were sent.
+func (s *Store) ListWSMessages(entryID int64) ([]WSMessage, error) {
+ rows, err := s.db.Query(
+ `SELECT id, entry_id, started_at, direction, opcode, payload FROM ws_messages WHERE entry_id = ? ORDER BY id`,
+ entryID,
+ )
+ if err != nil {
+ return nil, fmt.Errorf("list ws messages: %w", err)
+ }
+ defer rows.Close()
+
+ var out []WSMessage
+ for rows.Next() {
+ var m WSMessage
+ var startedAt int64
+ if err := rows.Scan(&m.ID, &m.EntryID, &startedAt, &m.Direction, &m.Opcode, &m.Payload); err != nil {
+ return nil, fmt.Errorf("scan ws message row: %w", err)
+ }
+ m.StartedAt = time.UnixMilli(startedAt)
+ out = append(out, m)
+ }
+ return out, rows.Err()
+}
+
// DeleteEntry removes a single history entry and its search index row.
func (s *Store) DeleteEntry(id int64) error {
tx, err := s.db.Begin()