srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/PLAN.md
diff options
context:
space:
mode:
Diffstat (limited to 'PLAN.md')
-rw-r--r--PLAN.md39
1 files changed, 39 insertions, 0 deletions
diff --git a/PLAN.md b/PLAN.md
index edaf599..90a27fd 100644
--- a/PLAN.md
+++ b/PLAN.md
@@ -206,6 +206,45 @@ rather than hanging or crashing.
This closes every item from the original "worth considering" list.
+## Post-audit hardening and history management
+
+A hands-on robustness audit (two parallel passes, backend and frontend,
+actually driving the daemon/TUI against adversarial input rather than
+reading code - "run it, don't read it") found and fixed six real bugs:
+raw ANSI/control-character injection from captured traffic reaching the
+operator's actual terminal (severe - confirmed a malicious Host value
+changed the real tmux pane title); a table-cursor desync that left
+enter/r/i/f/c inert on a live-captured entry until an unrelated
+navigation keypress; Intruder silently hanging 60s per payload on
+body-parameter fuzzing because Content-Length was never recalculated
+after marker substitution; match-and-replace rules accepting an invalid
+regex with zero validation or feedback, silently never firing; captures
+that hit the 10 MiB cap being marked "exact" anyway, hiding data loss
+from exactly the kind of investigation that needs the tail of a large
+body; and no timeouts anywhere, so a slow-loris connection or a client
+that completed CONNECT and never sent a TLS ClientHello held a
+connection and goroutine open forever. See commit history for full
+detail on each - every fix was verified against the actual failure
+mode, not just code-reviewed.
+
+Also added: history deletion. `Store` had full CRUD for rules but no
+way to delete or prune history - it only ever grew, with no way to
+remove an accidental capture or start fresh for a new engagement short
+of manually deleting the DB file outside the tool. `x` deletes the
+selected entry, `X` clears the entire database (explicitly not scoped
+to an active search filter - the confirmation always states the true
+total count, since understating it would make the prompt itself
+misleading about what's about to happen). Both gated behind a `y`/`n`
+confirmation: a small reusable confirmPrompt/confirmYes pattern in the
+TUI model, checked first in the history list's key handling, so any key
+other than y/Y safely cancels rather than falling through to whatever
+that key normally does.
+
+Still open from the expanded "worth considering" list: export/import
+(HAR, copy-as-curl), and scope/target filtering (to keep noise -
+trackers, CDNs, unrelated third-party hosts - out of history and
+search). Both requested explicitly; not started yet.
+
Skipped deliberately (from the research, matches this tool's stated
scope): active/passive vulnerability scanning, plugin marketplace,
Collaborator/OAST, team collaboration, CI integration, client TLS