srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/PLAN.md
diff options
context:
space:
mode:
Diffstat (limited to 'PLAN.md')
-rw-r--r--PLAN.md28
1 files changed, 28 insertions, 0 deletions
diff --git a/PLAN.md b/PLAN.md
index 64d1a0d..ca379e9 100644
--- a/PLAN.md
+++ b/PLAN.md
@@ -74,3 +74,31 @@ hudsucker) - same problem, worth studying even though this build is Go.
run in a loop with generated bytes - and results land in the same
history table tagged source="intruder", same as Repeater's
source="repeater", rather than a separate results store.
+
+## Post-build-order: Burp/ZAP/Caido parity pass
+
+Build order 1-7 is done. Researched what those three actually offer
+(features and basic UI/UX) and triaged the gap into "should build soon"
+/ "worth considering" / "skip" - see commit history for the full list;
+tracking what's shipped vs. deferred here.
+
+Shipped: vi-modal editing for the raw request textareas (table and
+viewport already had vi nav by default - this was specifically about
+textarea/textinput, which don't); a persistent status bar and a '?'
+keybinding reference; display-only response JSON pretty-printing;
+structured search filters (status:, source:, flagged:) alongside the
+existing FTS5 text search; a flagged marker (★) for "revisit this" -
+deliberately simpler than full free-text notes/comments, which would
+need their own text-input overlay for comparatively modest extra value
+over a boolean; noted as a real follow-up, not dropped silently.
+
+Still open from "worth considering": a Comparer (diff) tool, a
+standalone encoder/decoder utility, multiple concurrent Repeater tabs,
+Intruder payload processing (encoding/case rules) and grep-match/
+grep-extract on results, CA install UX per OS, multiple proxy listeners
+and upstream proxy chaining. None of these are started yet.
+
+Skipped deliberately (from the research, matches this tool's stated
+scope): active/passive vulnerability scanning, plugin marketplace,
+Collaborator/OAST, team collaboration, CI integration, client TLS
+(mutual-TLS) certs, invisible/non-proxy-aware proxying.