diff options
Diffstat (limited to 'PLAN.md')
| -rw-r--r-- | PLAN.md | 39 |
1 files changed, 37 insertions, 2 deletions
@@ -336,8 +336,43 @@ injection fix from the robustness audit, just for a different output format - captured content controlling the tool that later processes it, rather than the terminal that renders it. -Still open from the expanded "worth considering" list: import (no path -back in yet). Requested explicitly; not started yet. +Shipped since: import. `I` from the history list reads a HAR file and +inserts its entries into history, tagged source="import" (so +`source:import` finds them, same as `source:repeater`/`source:intruder` +already do). This closes the interop loop HAR export opened: traffic +can now move both directions between mitmux and any other HAR-producing +tool (browser DevTools, Burp, Postman), not just out. + +The reverse conversion (HAR entry -> raw HTTP/1.1 bytes) is the mirror +image of HAR export's harEntryFromDetail, deliberately written to +tolerate a HAR file that didn't come from mitmux at all - lowercase +header names, HTTP/2 in httpVersion, missing optional fields like +postData, a redirectURL nobody bothered filling in. Content-Encoding +and Transfer-Encoding headers are stripped from the reconstructed +response before writing it (HAR's content.text is already decoded per +spec - re-emitting those headers would describe framing the body no +longer has, breaking any client that tried to decode it again), and a +Content-Length is computed if the HAR didn't carry a consistent one. +Imported entries are always request_exact=false/response_exact=false - +reconstructed from structured HAR fields, same situation an HTTP/2 +capture is already in, never claiming to be the literal bytes that +were on the wire for the original request. An entry that fails to +convert (an unparseable URL, say) is skipped rather than failing the +whole import, same reasoning as export's own skip-and-continue. + +Verified live: exported real captured traffic to HAR, cleared history +entirely, imported the same file back and got both entries back with +correct content (byte-different from the original - headers get +reordered/reformatted through the round trip - but semantically +identical, and correctly labeled "reconstructed" rather than falsely +claiming "exact"); separately hand-built a HAR mimicking a real Chrome +DevTools export (lowercase headers, HTTP/2, a base64-encoded binary +PNG body, several optional fields omitted) and confirmed it imports +cleanly with the binary body correctly decoded (PNG magic bytes +verified byte-for-byte); confirmed a missing file and invalid JSON +both fail with a clear error and no crash, history left untouched. + +This closes every item from the expanded "worth considering" list. Skipped deliberately (from the research, matches this tool's stated scope): active/passive vulnerability scanning, plugin marketplace, |