diff options
Diffstat (limited to 'PLAN.md')
| -rw-r--r-- | PLAN.md | 39 |
1 files changed, 36 insertions, 3 deletions
@@ -272,12 +272,45 @@ Repeater request, say) is skipped rather than aborting the whole export - the status line reports how many, so a partial export is visible, not silent. +Shipped since: target scope. `s` from the history list opens scope +management - add/toggle/delete rules matching a host by substring +(case-insensitive, so "example.com" matches "www.example.com" and +"api.example.com" too, covering "this domain and its subdomains" +without a separate wildcard syntax) or by regex, mirroring the same +Match-text-or-regex toggle match-and-replace rules already use for one +consistent mental model. No rules configured (or none enabled) means +everything is recorded - today's behavior before scope existed at all, +unchanged, so a fresh install or a user who never opens the scope view +keeps recording everything rather than silently nothing. + +Scope only filters what gets recorded, not what gets proxied: an +out-of-scope request still reaches its destination and its response +still reaches the client completely normally (see `internal/proxy`'s +`forward()` - the response is already written to the client by the +time the scope check runs; skipping the record step only skips +storage). This was a deliberate choice over blocking out-of-scope +traffic outright, which would be a materially different, much riskier +feature - an access-control mechanism, not a noise filter, and a wrong +scope pattern could silently break the very traffic the user is trying +to test. Repeater and Intruder deliberately bypass the scope check +entirely (recordRaw, a separate code path from the passive-capture +record()): a user explicitly resending or fuzzing a specific request +wants to see the result regardless of scope, which exists to cut +passive-capture noise (CDNs, analytics, trackers, unrelated third-party +hosts), not to second-guess a deliberate action. Verified live: added a +substring scope rule for one host, confirmed a request to a +non-matching host still proxied successfully (200 response reached the +client) but was never recorded, confirmed the matching host's requests +were recorded, confirmed a Repeater resend of the excluded host WAS +recorded despite being out of scope, confirmed toggling the rule off +resumed recording everything, and confirmed both the substring and +regex pattern forms save and match correctly. + Still open from the expanded "worth considering" list: import (no path back in yet - HAR export was prioritized as the more common daily need, getting captured evidence OUT for a report or another tool, over -bringing traffic IN), copy-as-curl, and scope/target filtering (to keep -noise - trackers, CDNs, unrelated third-party hosts - out of history -and search). All requested explicitly; none started yet. +bringing traffic IN) and copy-as-curl. Both requested explicitly; not +started yet. Skipped deliberately (from the research, matches this tool's stated scope): active/passive vulnerability scanning, plugin marketplace, |