diff options
Diffstat (limited to 'PLAN.md')
| -rw-r--r-- | PLAN.md | 28 |
1 files changed, 28 insertions, 0 deletions
@@ -74,3 +74,31 @@ hudsucker) - same problem, worth studying even though this build is Go. run in a loop with generated bytes - and results land in the same history table tagged source="intruder", same as Repeater's source="repeater", rather than a separate results store. + +## Post-build-order: Burp/ZAP/Caido parity pass + +Build order 1-7 is done. Researched what those three actually offer +(features and basic UI/UX) and triaged the gap into "should build soon" +/ "worth considering" / "skip" - see commit history for the full list; +tracking what's shipped vs. deferred here. + +Shipped: vi-modal editing for the raw request textareas (table and +viewport already had vi nav by default - this was specifically about +textarea/textinput, which don't); a persistent status bar and a '?' +keybinding reference; display-only response JSON pretty-printing; +structured search filters (status:, source:, flagged:) alongside the +existing FTS5 text search; a flagged marker (★) for "revisit this" - +deliberately simpler than full free-text notes/comments, which would +need their own text-input overlay for comparatively modest extra value +over a boolean; noted as a real follow-up, not dropped silently. + +Still open from "worth considering": a Comparer (diff) tool, a +standalone encoder/decoder utility, multiple concurrent Repeater tabs, +Intruder payload processing (encoding/case rules) and grep-match/ +grep-extract on results, CA install UX per OS, multiple proxy listeners +and upstream proxy chaining. None of these are started yet. + +Skipped deliberately (from the research, matches this tool's stated +scope): active/passive vulnerability scanning, plugin marketplace, +Collaborator/OAST, team collaboration, CI integration, client TLS +(mutual-TLS) certs, invisible/non-proxy-aware proxying. |