srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/PLAN.md
diff options
context:
space:
mode:
Diffstat (limited to 'PLAN.md')
-rw-r--r--PLAN.md39
1 files changed, 36 insertions, 3 deletions
diff --git a/PLAN.md b/PLAN.md
index 4864012..a3ca810 100644
--- a/PLAN.md
+++ b/PLAN.md
@@ -272,12 +272,45 @@ Repeater request, say) is skipped rather than aborting the whole
export - the status line reports how many, so a partial export is
visible, not silent.
+Shipped since: target scope. `s` from the history list opens scope
+management - add/toggle/delete rules matching a host by substring
+(case-insensitive, so "example.com" matches "www.example.com" and
+"api.example.com" too, covering "this domain and its subdomains"
+without a separate wildcard syntax) or by regex, mirroring the same
+Match-text-or-regex toggle match-and-replace rules already use for one
+consistent mental model. No rules configured (or none enabled) means
+everything is recorded - today's behavior before scope existed at all,
+unchanged, so a fresh install or a user who never opens the scope view
+keeps recording everything rather than silently nothing.
+
+Scope only filters what gets recorded, not what gets proxied: an
+out-of-scope request still reaches its destination and its response
+still reaches the client completely normally (see `internal/proxy`'s
+`forward()` - the response is already written to the client by the
+time the scope check runs; skipping the record step only skips
+storage). This was a deliberate choice over blocking out-of-scope
+traffic outright, which would be a materially different, much riskier
+feature - an access-control mechanism, not a noise filter, and a wrong
+scope pattern could silently break the very traffic the user is trying
+to test. Repeater and Intruder deliberately bypass the scope check
+entirely (recordRaw, a separate code path from the passive-capture
+record()): a user explicitly resending or fuzzing a specific request
+wants to see the result regardless of scope, which exists to cut
+passive-capture noise (CDNs, analytics, trackers, unrelated third-party
+hosts), not to second-guess a deliberate action. Verified live: added a
+substring scope rule for one host, confirmed a request to a
+non-matching host still proxied successfully (200 response reached the
+client) but was never recorded, confirmed the matching host's requests
+were recorded, confirmed a Repeater resend of the excluded host WAS
+recorded despite being out of scope, confirmed toggling the rule off
+resumed recording everything, and confirmed both the substring and
+regex pattern forms save and match correctly.
+
Still open from the expanded "worth considering" list: import (no path
back in yet - HAR export was prioritized as the more common daily need,
getting captured evidence OUT for a report or another tool, over
-bringing traffic IN), copy-as-curl, and scope/target filtering (to keep
-noise - trackers, CDNs, unrelated third-party hosts - out of history
-and search). All requested explicitly; none started yet.
+bringing traffic IN) and copy-as-curl. Both requested explicitly; not
+started yet.
Skipped deliberately (from the research, matches this tool's stated
scope): active/passive vulnerability scanning, plugin marketplace,