From 80354144ddc39d33204ab47153c33bdb111b5544 Mon Sep 17 00:00:00 2001 From: srdusr <99972264+srdusr@users.noreply.github.com> Date: Tue, 17 Mar 2026 09:44:00 +0200 Subject: Standalone Decoder: URL/Base64/Hex/HTML encode & decode First of the remaining "worth considering" items. A self-contained tool ('d' from the history list, not seeded from any entry - this is for arbitrary snippets, pasted tokens, encoded parameter values) with a vi-modal input pane and a live output pane that updates on every keystroke and every transform switch (tab/shift+tab cycles through the 8 transforms). decoder.go is pure logic, deliberately kept separate from the TUI wiring so it's directly testable: urlEncodeAll implements strict RFC 3986 percent-encoding (space -> %20) rather than using Go's url.QueryEscape, whose form-encoding behavior (space -> '+') isn't what "URL encode" means to a pentester reaching for this tool. Base64 decode tries standard/URL-safe/padded/unpadded encodings in turn rather than requiring the user to know which one they're looking at - real pasted data is as likely to be one as the other. Decode failures return a visible "(error: ...)" placeholder rather than blanking the output, so a bad guess at the transform is obviously wrong rather than looking like nothing happened. decoder_test.go covers each transform directly, three "this input isn't valid for this transform" error cases, and a round-trip matrix (all 4 encode/decode pairs against 5 inputs chosen to be awkward for at least one encoding - spaces, slashes, HTML-special characters, empty string, embedded newlines) confirming encode-then-decode always recovers the original. Single-transform only, not chained/pipelined like Burp's Decoder - v1 scope, tracked in PLAN.md. Verified live: typed text and watched the output pane update in real time; confirmed URL-encoding, then cycled to Base64 via tab and watched it re-encode the same input live; confirmed the active-transform highlighting via raw ANSI codes in the captured pane; fed invalid input to Base64 decode and confirmed the error placeholder renders instead of silently showing stale output; confirmed esc correctly backs out to the history list. --- README.md | 13 +++++++++++++ 1 file changed, 13 insertions(+) (limited to 'README.md') diff --git a/README.md b/README.md index c3f2d92..9bc683e 100644 --- a/README.md +++ b/README.md @@ -50,6 +50,8 @@ list of what's deliberately not implemented (and why), see `flagged:true`. - **Comparer**: mark one entry (`c`), then `c` on a different entry to see a colored unified diff of either side's request or response. +- **Decoder**: standalone URL/Base64/Hex/HTML encode and decode (`d`), + output updates live as you type or switch transforms. - **Vi-modal editing**: the raw request editors (Repeater, Intruder) are real modal editors - normal mode by default, `i`/`a`/`o`/etc. to insert, `hjkl`, `dd`/`yy`/`p`, word motions, `gg`/`G`. See @@ -124,6 +126,7 @@ below is enough to get going. | `i` | open in Intruder | | `f` | toggle flag | | `c` | mark for comparison - press `c` on another entry to diff | +| `d` | Decoder | | `/` | search | | `m` | match-and-replace rules | | `q` | quit | @@ -144,6 +147,16 @@ style, `+`/`-` lines - of the two entries' requests or responses, exact HTTP/1.1 capture doesn't show every line as changed purely from the invisible `\r`. +### Decoder + +Reachable with `d` from the history list - a standalone tool, not seeded +from any entry. `i` to type or paste text; the output pane updates live +as you type. `tab`/`shift+tab` cycles through URL, Base64, and Hex +encode/decode and HTML entity encode/decode. Base64 decode tries the +standard, URL-safe, padded, and unpadded variants in turn rather than +requiring you to know which one you're looking at. Single-transform +only - not chained/pipelined the way Burp's Decoder supports. + ### Search syntax Plain text searches headers and bodies on both sides of the exchange. -- cgit v1.2.3