From dd1621c0077e079e0693f16fe83f17d50338216e Mon Sep 17 00:00:00 2001 From: srdusr <99972264+srdusr@users.noreply.github.com> Date: Fri, 15 May 2026 19:48:00 +0200 Subject: Stop mislabeling truncated captures as "exact" internal/proxy/tee.go's teeConn silently drops bytes past maxCaptureBytes (10 MiB) but callers unconditionally marked the result "exact" anyway. Confirmed live: proxying a 15 MiB response worked correctly end-to-end (the client got the full, real 15 MiB - proxying itself is unbounded, only storage is capped), but the stored history entry was exactly 10485760 bytes with response_exact=1 still set. For a tool whose core value proposition is "raw bytes are the source of truth," a silently truncated capture presented as complete could hide the very evidence a smuggling or parser-differential investigation is looking for in the tail of a large body - and give false confidence that it isn't there. teeConn.Take() now returns (data, truncated) instead of just data; truncated is true whenever a Read had to drop bytes because the buffer was already at cap. Every caller (proxy.go's forward() on both the request and response side, repeat.go's sendRaw for Repeater/Intruder) now folds truncated into exact - a truncated capture is never marked exact - and additionally threads a distinct RequestTruncated/ ResponseTruncated bool through store.Entry, ipc.EntryDetail, and the TUI, since "truncated" and "reconstructed" (HTTP/2, which never had wire-exact bytes to begin with) are different situations worth telling apart: a truncated capture is still real wire bytes, just incomplete, not a synthesized reconstruction. The detail/repeater views now show "truncated (hit capture size limit)" specifically rather than lumping it in with "reconstructed", which would have implied more transformation happened than actually did. Schema: history gains request_truncated/response_truncated columns via the same ALTER-TABLE-and-ignore-duplicate-column pattern already used for source/flagged, so existing databases upgrade in place. Verified live: a target server returning a 15 MiB body (over the 10 MiB cap) proxied through cleanly - full body reached the client - while the stored entry shows length=10485760, response_exact=0, response_truncated=1 (previously would have shown response_exact=1); the TUI's Detail view correctly displays "Response (10485760 bytes, truncated (hit capture size limit))" instead of "exact". go build/vet/gofmt/test/mod tidy all clean. --- internal/proxy/repeat.go | 38 ++++++++++++++++++++------------------ 1 file changed, 20 insertions(+), 18 deletions(-) (limited to 'internal/proxy/repeat.go') diff --git a/internal/proxy/repeat.go b/internal/proxy/repeat.go index 3ee7cea..f682b99 100644 --- a/internal/proxy/repeat.go +++ b/internal/proxy/repeat.go @@ -38,7 +38,7 @@ func (s *Server) sendRaw(ctx context.Context, scheme, host string, raw []byte, s conn, err := dialForRepeat(ctx, scheme, host) if err != nil { - return s.recordRaw(started, time.Since(started), scheme, host, method, path, raw, nil, 0, err.Error(), source) + return s.recordRaw(started, time.Since(started), scheme, host, method, path, raw, nil, false, false, 0, err.Error(), source) } defer conn.Close() // See the matching comment in forward(): without this, a hung @@ -48,37 +48,39 @@ func (s *Server) sendRaw(ctx context.Context, scheme, host string, raw []byte, s conn.SetDeadline(time.Now().Add(upstreamTimeout)) if _, err := conn.Write(raw); err != nil { - return s.recordRaw(started, time.Since(started), scheme, host, method, path, raw, nil, 0, err.Error(), source) + return s.recordRaw(started, time.Since(started), scheme, host, method, path, raw, nil, false, false, 0, err.Error(), source) } tee := newTeeConn(conn) resp, err := http.ReadResponse(bufio.NewReader(tee), &http.Request{Method: method}) duration := time.Since(started) if err != nil { - return s.recordRaw(started, duration, scheme, host, method, path, raw, nil, 0, err.Error(), source) + return s.recordRaw(started, duration, scheme, host, method, path, raw, nil, false, false, 0, err.Error(), source) } defer resp.Body.Close() io.Copy(io.Discard, resp.Body) - return s.recordRaw(started, duration, scheme, host, method, path, raw, tee.Take(), resp.StatusCode, "", source) + respRaw, truncated := tee.Take() + return s.recordRaw(started, duration, scheme, host, method, path, raw, respRaw, !truncated, truncated, resp.StatusCode, "", source) } func (s *Server) recordRaw(started time.Time, duration time.Duration, scheme, host, method, path string, - reqRaw, respRaw []byte, status int, errMsg, source string) (*store.Entry, error) { + reqRaw, respRaw []byte, respExact, respTruncated bool, status int, errMsg, source string) (*store.Entry, error) { e := &store.Entry{ - StartedAt: started, - Duration: duration, - Method: method, - Scheme: scheme, - Host: host, - Path: path, - StatusCode: status, - RequestRaw: reqRaw, - ResponseRaw: respRaw, - RequestExact: true, - ResponseExact: respRaw != nil, - Error: errMsg, - Source: source, + StartedAt: started, + Duration: duration, + Method: method, + Scheme: scheme, + Host: host, + Path: path, + StatusCode: status, + RequestRaw: reqRaw, + ResponseRaw: respRaw, + RequestExact: true, + ResponseExact: respRaw != nil && respExact, + ResponseTruncated: respRaw != nil && respTruncated, + Error: errMsg, + Source: source, } if s.store != nil { id, err := s.store.Insert(e) -- cgit v1.2.3