srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/PLAN.md
diff options
context:
space:
mode:
Diffstat (limited to 'PLAN.md')
-rw-r--r--PLAN.md35
1 files changed, 31 insertions, 4 deletions
diff --git a/PLAN.md b/PLAN.md
index a3ca810..a070b20 100644
--- a/PLAN.md
+++ b/PLAN.md
@@ -306,11 +306,38 @@ recorded despite being out of scope, confirmed toggling the rule off
resumed recording everything, and confirmed both the substring and
regex pattern forms save and match correctly.
+Shipped since: CSV export and copy-as-curl, both extending the existing
+export system by dispatching on the file extension the user types
+rather than adding a separate format-selection control - ".har" (the
+existing default) or ".csv" for bulk export from the history list,
+".txt" (the existing default) or ".sh"/".curl" for single-entry export
+from Detail view. CSV is deliberately a lighter, faster path than HAR:
+a summary table (id/method/host/path/status/sizes/timing/flag/source)
+built straight from the already-loaded Summary rows, no per-entry fetch
+from the daemon needed, matching Burp's own "export as CSV" being a
+listing rather than a full-fidelity capture - HAR already covers that.
+Copy-as-curl parses the raw request (same net/http parsing used
+everywhere else in this codebase) and re-serializes it as a runnable
+curl command line rather than another copy of the raw bytes, which the
+plain-text format already gives you; verified by actually executing a
+generated command against the real target and confirming the response
+matched the original.
+
+CSV export required one more thing HAR didn't: guarding against CSV/
+formula injection. Method, host, path, and error all ultimately trace
+back to a request line or Host header - content this tool exists
+specifically to inspect from potentially hostile traffic - and a field
+starting with =, +, -, @, tab, or CR is a formula to Excel/LibreOffice/
+Sheets when the exported file is later opened. csvSafe prefixes any
+such field with a single quote, the standard mitigation (OWASP's own
+guidance), so every affected spreadsheet application treats it as
+literal text instead. This is the same class of bug as the terminal-
+injection fix from the robustness audit, just for a different output
+format - captured content controlling the tool that later processes it,
+rather than the terminal that renders it.
+
Still open from the expanded "worth considering" list: import (no path
-back in yet - HAR export was prioritized as the more common daily need,
-getting captured evidence OUT for a report or another tool, over
-bringing traffic IN) and copy-as-curl. Both requested explicitly; not
-started yet.
+back in yet). Requested explicitly; not started yet.
Skipped deliberately (from the research, matches this tool's stated
scope): active/passive vulnerability scanning, plugin marketplace,