diff options
Diffstat (limited to 'PLAN.md')
| -rw-r--r-- | PLAN.md | 21 |
1 files changed, 15 insertions, 6 deletions
@@ -99,13 +99,22 @@ anything but a narrow window, and unified reuses the same scrollable- viewport pattern already used everywhere else in the TUI. CRLF is normalized to LF before diffing (display-only, same reasoning as the JSON pretty-printer) so an HTTP/1.1 exact capture doesn't show every -line as changed from an invisible trailing \r. +line as changed from an invisible trailing \r; a standalone Decoder +tool ('d') - URL/Base64/Hex/HTML encode and decode, live output as you +type, tab to cycle transforms. Deliberately single-transform, not +chained/pipelined like Burp's Decoder - v1 scope, and pipeline-building +UI is real added complexity for a feature that's already useful without +it. Base64 decode tries standard/URL-safe/padded/unpadded variants in +turn rather than making the user pick, since real pasted data is as +likely to be one as the other. URL encode/decode uses strict RFC 3986 +percent-encoding (space <-> %20), not Go's url.QueryEscape's form- +encoding behavior (space <-> '+'), since "URL encode" for a pentester +almost always means the former. -Still open from "worth considering": a standalone encoder/decoder -utility, multiple concurrent Repeater tabs, Intruder payload processing -(encoding/case rules) and grep-match/grep-extract on results, CA install -UX per OS, multiple proxy listeners and upstream proxy chaining. None -of these are started yet. +Still open from "worth considering": multiple concurrent Repeater tabs, +Intruder payload processing (encoding/case rules) and grep-match/ +grep-extract on results, CA install UX per OS, multiple proxy listeners +and upstream proxy chaining. None of these are started yet. Skipped deliberately (from the research, matches this tool's stated scope): active/passive vulnerability scanning, plugin marketplace, |