diff options
Diffstat (limited to 'include/wireframe/search.hpp')
| -rw-r--r-- | include/wireframe/search.hpp | 26 |
1 files changed, 26 insertions, 0 deletions
diff --git a/include/wireframe/search.hpp b/include/wireframe/search.hpp new file mode 100644 index 0000000..4cb9203 --- /dev/null +++ b/include/wireframe/search.hpp @@ -0,0 +1,26 @@ +#pragma once + +#include <algorithm> +#include <cctype> +#include <string> + +// A display filter, distinct from -f's capture filter (wireframe/filter.hpp): +// -f decides what's captured - and, combined with -w, what's written to +// disk. This decides what's shown, without touching either. Same +// distinction Wireshark draws between a capture filter and a display +// filter, just without the display filter's expression language - a +// plain case-insensitive substring match over the packet's summary line +// is enough for "find the packets mentioning this host/port", which is +// the actual use case. +namespace wireframe { + +inline bool matches_search(const std::string& haystack, const std::string& needle) { + if (needle.empty()) return true; + auto it = std::search(haystack.begin(), haystack.end(), needle.begin(), needle.end(), + [](unsigned char a, unsigned char b) { + return std::tolower(a) == std::tolower(b); + }); + return it != haystack.end(); +} + +} // namespace wireframe |