mirror of https://github.com/vee1e/mitmproxy - An interactive TLS-capable intercepting HTTP proxy for penet
Find a file
Maximilian Hils 8fa4717fc2
Hardening: unify header validation across HTTP versions (#7343)
* hardening: unify header validation across HTTP versions

This is meant to prevent request smuggling attacks over different HTTP versions.

* docs++, reject transfer-encoding for HTTP/1.0

* [autofix.ci] apply automated fixes

* tests++

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
2024-11-24 22:45:13 +00:00
.github Bump the github-actions group with 2 updates (#7299) 2024-11-01 23:56:22 +01:00
docs Remove Apple Silicon note (#7234) 2024-10-11 00:44:07 +02:00
examples Update change_upstream_proxy.py (#6853) 2024-05-18 12:06:48 +02:00
mitmproxy Hardening: unify header validation across HTTP versions (#7343) 2024-11-24 22:45:13 +00:00
release Docker: use latest python and debian (#7242) 2024-10-13 18:21:57 +02:00
test Hardening: unify header validation across HTTP versions (#7343) 2024-11-24 22:45:13 +00:00
web Align web/gen and ruff format (#7342) 2024-11-23 06:20:26 +01:00
.gitattributes
.gitignore fix display of error messages on early shutdown (#6719) 2024-03-07 20:41:26 +00:00
CHANGELOG.md Hardening: unify header validation across HTTP versions (#7343) 2024-11-24 22:45:13 +00:00
codecov.yml
CONTRIBUTING.md
LICENSE
MANIFEST.in
pyproject.toml Update hypothesis requirement from <=6.116.0,>=6.104.2 to >=6.104.2,<=6.119.3 in the pytest group (#7328) 2024-11-18 09:23:45 +00:00
README.md Remove Links to Slack Workspace (#6560) 2023-12-19 12:20:43 +00:00
SECURITY.md

mitmproxy

Continuous Integration Status Codacy Badge autofix.ci: enabled Coverage Status Latest Version Supported Python versions

mitmproxy is an interactive, SSL/TLS-capable intercepting proxy with a console interface for HTTP/1, HTTP/2, and WebSockets.

mitmdump is the command-line version of mitmproxy. Think tcpdump for HTTP.

mitmweb is a web-based interface for mitmproxy.

Installation

The installation instructions are here. If you want to install from source, see CONTRIBUTING.md.

Documentation & Help

General information, tutorials, and precompiled binaries can be found on the mitmproxy website.

mitmproxy.org

The documentation for mitmproxy is available on our website:

mitmproxy documentation stable mitmproxy documentation dev

If you have questions on how to use mitmproxy, please use GitHub Discussions!

mitmproxy discussions

Contributing

As an open source project, mitmproxy welcomes contributions of all forms.

Dev Guide