From 2bb1425dd0da46d8a3df0b888411f21340783d71 Mon Sep 17 00:00:00 2001 From: srdusr <99972264+srdusr@users.noreply.github.com> Date: Wed, 18 Mar 2026 16:15:00 +0200 Subject: Multiple concurrent Repeater tabs Repeater previously had one shared request/response buffer - sending a new entry to Repeater silently overwrote whatever was already open, even mid-edit. Replaced the singular reqArea/respView/repeaterScheme/ etc. model fields with a []*repeaterTab slice plus an active index; 'r' now opens a new tab and switches to it, existing tabs stay put. New keys, all gated to normal mode so they stay inert while typing (]/[ show up in JSON bodies constantly, and ctrl+w is the textarea's own delete-word-backward that must still work mid-edit): ] next tab [ previous tab ctrl+w close the active tab (falls back to a neighbor, or to the history list if it was the last one) Async send results now carry the tab index they belong to, so a slow send whose response lands after the user has switched tabs (or closed one) updates the right tab rather than whichever happens to be active when the result arrives; the status line and response pane only reflect it live if that tab is still the one being viewed. Verified live in tmux against a running daemon: opened two tabs from different history entries, confirmed independent buffers, sent from a background tab while another was active and confirmed the result routed to the correct (non-visible) tab, switched with ]/[, closed with ctrl+w down to zero tabs (falls back to the history list), and confirmed [, ], and ctrl+w are all correctly inert in insert mode (typed "[a]" literally, ctrl+w did textarea's word-delete instead of closing the tab). go build/vet/gofmt/test/mod tidy all clean. --- PLAN.md | 21 +++++++++++++++++---- 1 file changed, 17 insertions(+), 4 deletions(-) (limited to 'PLAN.md') diff --git a/PLAN.md b/PLAN.md index 67e0e77..2dac629 100644 --- a/PLAN.md +++ b/PLAN.md @@ -111,10 +111,23 @@ percent-encoding (space <-> %20), not Go's url.QueryEscape's form- encoding behavior (space <-> '+'), since "URL encode" for a pentester almost always means the former. -Still open from "worth considering": multiple concurrent Repeater tabs, -Intruder payload processing (encoding/case rules) and grep-match/ -grep-extract on results, CA install UX per OS, multiple proxy listeners -and upstream proxy chaining. None of these are started yet. +Shipped since: a standalone Decoder tool ('d') - see above; multiple +concurrent Repeater tabs - 'r' from the history list or detail view now +opens a NEW tab rather than overwriting whatever was already open, +`]`/`[` switch tabs, `ctrl+w` closes the active one (all three gated to +normal mode, so they're inert while typing - `[`/`]` are common JSON +body characters and `ctrl+w` is a textarea binding for delete-word- +backward that must still work while composing a request). Each tab owns +its own request buffer, response view, and send-in-flight state; a slow +send whose result lands after the user has switched away still updates +the correct tab (send results carry the tab index they belong to), and +the status line/response pane it's shown in only updates live if that +tab is still the one on screen. + +Still open from "worth considering": Intruder payload processing +(encoding/case rules) and grep-match/grep-extract on results, CA install +UX per OS, multiple proxy listeners and upstream proxy chaining. None of +these are started yet. Skipped deliberately (from the research, matches this tool's stated scope): active/passive vulnerability scanning, plugin marketplace, -- cgit v1.2.3