diff options
Diffstat (limited to 'PLAN.md')
| -rw-r--r-- | PLAN.md | 35 |
1 files changed, 31 insertions, 4 deletions
@@ -306,11 +306,38 @@ recorded despite being out of scope, confirmed toggling the rule off resumed recording everything, and confirmed both the substring and regex pattern forms save and match correctly. +Shipped since: CSV export and copy-as-curl, both extending the existing +export system by dispatching on the file extension the user types +rather than adding a separate format-selection control - ".har" (the +existing default) or ".csv" for bulk export from the history list, +".txt" (the existing default) or ".sh"/".curl" for single-entry export +from Detail view. CSV is deliberately a lighter, faster path than HAR: +a summary table (id/method/host/path/status/sizes/timing/flag/source) +built straight from the already-loaded Summary rows, no per-entry fetch +from the daemon needed, matching Burp's own "export as CSV" being a +listing rather than a full-fidelity capture - HAR already covers that. +Copy-as-curl parses the raw request (same net/http parsing used +everywhere else in this codebase) and re-serializes it as a runnable +curl command line rather than another copy of the raw bytes, which the +plain-text format already gives you; verified by actually executing a +generated command against the real target and confirming the response +matched the original. + +CSV export required one more thing HAR didn't: guarding against CSV/ +formula injection. Method, host, path, and error all ultimately trace +back to a request line or Host header - content this tool exists +specifically to inspect from potentially hostile traffic - and a field +starting with =, +, -, @, tab, or CR is a formula to Excel/LibreOffice/ +Sheets when the exported file is later opened. csvSafe prefixes any +such field with a single quote, the standard mitigation (OWASP's own +guidance), so every affected spreadsheet application treats it as +literal text instead. This is the same class of bug as the terminal- +injection fix from the robustness audit, just for a different output +format - captured content controlling the tool that later processes it, +rather than the terminal that renders it. + Still open from the expanded "worth considering" list: import (no path -back in yet - HAR export was prioritized as the more common daily need, -getting captured evidence OUT for a report or another tool, over -bringing traffic IN) and copy-as-curl. Both requested explicitly; not -started yet. +back in yet). Requested explicitly; not started yet. Skipped deliberately (from the research, matches this tool's stated scope): active/passive vulnerability scanning, plugin marketplace, |