srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/README.md
diff options
context:
space:
mode:
Diffstat (limited to 'README.md')
-rw-r--r--README.md23
1 files changed, 23 insertions, 0 deletions
diff --git a/README.md b/README.md
index f0bcc0c..de8274e 100644
--- a/README.md
+++ b/README.md
@@ -162,6 +162,7 @@ below is enough to get going.
| `d` | Decoder |
| `/` | search |
| `m` | match-and-replace rules |
+| `s` | target scope (what gets recorded) |
| `q` | quit |
### Detail view
@@ -307,6 +308,27 @@ text, not per-value substitution, so a rule can add or remove a header
entirely, not just rewrite an existing one. Currently headers only -
see `PLAN.md` for why body rules are a separate, harder problem.
+### Scope
+
+Press `s` from the history view to manage what gets **recorded** to
+history - not what gets proxied. Out-of-scope traffic still reaches its
+destination and the response still reaches the client completely
+normally; it's just not stored, so unrelated CDN/analytics/tracker
+noise doesn't pollute history and search on a real engagement. No rules
+(or none enabled) means everything is recorded, same as before scope
+existed.
+
+`a` adds a rule (a pattern, and `tab` to toggle regex matching - same
+Match-text-or-regex model as match-and-replace rules), `space` toggles
+one on/off, `d` deletes the selected one. A non-regex pattern matches
+by case-insensitive substring against the host - `example.com` matches
+`example.com`, `www.example.com`, and `api.example.com` alike, covering
+"this domain and its subdomains" without a separate wildcard syntax.
+
+Repeater and Intruder always record regardless of scope - a request you
+deliberately resend or fuzz is something you clearly want to see the
+result of, not noise scope exists to cut.
+
## Architecture
`mitmuxd` owns the proxy listener and the SQLite database; `mitmux` is
@@ -336,6 +358,7 @@ cmd/mitmux/ TUI entrypoint
internal/ca/ root CA + per-host leaf certificate generation
internal/proxy/ proxy engine: HTTP/CONNECT handling, capture, Repeater, Intruder
internal/rules/ match-and-replace engine
+internal/scope/ target scope (what gets recorded)
internal/store/ SQLite storage, FTS5 search
internal/ipc/ daemon <-> client protocol (JSON over a Unix socket)
```