diff options
Diffstat (limited to 'internal/proxy')
| -rw-r--r-- | internal/proxy/proxy.go | 34 |
1 files changed, 34 insertions, 0 deletions
diff --git a/internal/proxy/proxy.go b/internal/proxy/proxy.go index 014c601..3b2d50d 100644 --- a/internal/proxy/proxy.go +++ b/internal/proxy/proxy.go @@ -35,6 +35,7 @@ import ( "golang.org/x/net/http2" "mitmux/internal/ca" + "mitmux/internal/rules" "mitmux/internal/store" ) @@ -244,6 +245,17 @@ func (s *Server) forward(dial dialer, scheme, hostname string, w http.ResponseWr outReq.URL.Host = hostname outReq.RequestURI = "" stripHopByHop(outReq.Header) + // Header rules are applied to outReq only, after cloning and header + // stripping - history's request_raw keeps showing what the client + // actually sent (clientTee/reqBodyCap already capture from r, not + // outReq), while what actually reaches the upstream server reflects + // the rules. That split is deliberate: match-and-replace is a wire + // transform, not a rewrite of the audit trail. + if reqRules, err := s.enabledRules("request"); err != nil { + log.Printf("load request rules: %v", err) + } else if len(reqRules) > 0 { + outReq.Header = rules.ApplyHeaders(outReq.Header, reqRules) + } // Only needed when the client leg isn't tee-captured (HTTP/2): tee // the body as it streams through so the reconstructed capture isn't @@ -297,6 +309,17 @@ func (s *Server) forward(dial dialer, scheme, hostname string, w http.ResponseWr resp.Body = io.NopCloser(respBodyCap) } + // Same split as the request side: response_raw keeps reflecting what + // the origin server actually sent (captured below, from upstreamTee + // or respBodyCap, both already wired to resp.Body independent of + // resp.Header), while the client actually receives the rule-modified + // headers. + if respRules, err := s.enabledRules("response"); err != nil { + log.Printf("load response rules: %v", err) + } else if len(respRules) > 0 { + resp.Header = rules.ApplyHeaders(resp.Header, respRules) + } + stripHopByHop(resp.Header) for k, vv := range resp.Header { for _, v := range vv { @@ -317,6 +340,17 @@ func (s *Server) forward(dial dialer, scheme, hostname string, w http.ResponseWr s.record(started, duration, scheme, hostname, r, reqRaw, reqExact, respRaw, respExact, resp.StatusCode, "") } +// enabledRules fetches the current enabled match-and-replace rules for +// scope ("request" or "response") fresh from the store on every call - +// simple and always current, and cheap enough (a local, in-process +// SQLite query) not to bother caching for how this is actually used. +func (s *Server) enabledRules(scope string) ([]rules.Rule, error) { + if s.store == nil { + return nil, nil + } + return s.store.EnabledRules(scope) +} + // record stores one history entry and notifies OnEntry. func (s *Server) record(started time.Time, duration time.Duration, scheme, host string, r *http.Request, reqRaw []byte, reqExact bool, respRaw []byte, respExact bool, status int, errMsg string) { |