Skip to content

v1.1.0: expand Interceptor into a complete local HTTP workbench - #1

Merged
user-github-me merged 5 commits into
mainfrom
feat/v1.1-workbench
Oct 3, 2026
Merged

user-github-me merged 5 commits into
mainfrom
feat/v1.1-workbench

Conversation

@user-github-me

@user-github-me user-github-me commented Oct 3, 2026 •

Copy link
Copy Markdown
Owner

Interceptor now supports a complete local request workflow: capture traffic, inspect fields, replay or vary requests, compare responses, and keep reusable requests in Collections. All unpublished work is combined into version 1.1.0.

Changes

  • Refined dark/light UI with responsive layouts, keyboard navigation, and useful empty states.
  • Added Site Map, Inspector, payload Runner, Collections/variables, Comparer, Decoder, and HAR import.
  • Added cURL import, response snapshots, request duplication, timeouts, result checks/CSV export, and Ctrl/Command+K tool switching.
  • Added Postman-style API Builder with authentication, JSON/form/raw bodies, saved response assertions, and Postman collection import.
  • Added passive Security Review, contextual header/CORS/cookie/cache/error observations, review status and reports, plus controlled credential-header comparisons.
  • Added passive live WebSocket frames, filtering, export, and Decoder integration.
  • Saved complete workspaces automatically in local IndexedDB: history, drafts, responses/snapshots, collections, variables/environments, findings, frames, and test results.
  • Added full backup/import, validation and preview, restore without traffic, local undo, and optional AES-256-GCM / PBKDF2 password encryption.
  • Added URL include/exclude scope for Auto mode and session-only tab targeting.
  • Preserved unrelated JSON/query bytes and large numeric values; protected incomplete/oversized uploads and multipart files.
  • Serialized temporary Repeater header rules and cleaned them after completion, timeout, cancellation, or dashboard closure.
  • Preserved legacy Repeater drafts and Collections; portable collection exports omit variables while full backups include them. All data stays on the user's PC.
  • Updated public documentation/privacy policy/screenshots and recorded the PR-only repository workflow.

Validation

  • npm test: 29 regression tests passed.
  • npm run check: all ten runtime JavaScript files passed syntax checks.
  • git diff --check: passed.
  • Real Brave 154 integration with local HTTP/WebSocket fixtures passed: intercept/Auto/handoff, uploads, headers/cleanup, HAR, Site Map, Inspector, Runner/cancellation/timeouts, snapshots, cURL UI, Builder auth/assertions, credential comparisons, live frames in both directions, encrypted full backup/restore and complete workspace reload. Restoration sends no requests. No runtime exceptions.
  • Desktop dark/light and narrow layouts inspected. Runtime-only ZIP prepared locally with manifest at root.

Scope

No new permissions or runtime dependencies. Passive findings are observations, not confirmed vulnerabilities. WebSocket frames are observed, not injected. Credential comparison accepts GET/HEAD/OPTIONS and strips credential headers only. Browser protocol/preview/storage limitations are documented. This PR remains v1.1.0 and is not merged or store-published.

The store update remains unpublished. Runner is sequential, capped at 50 payloads per origin, and uses bounded previews. Site Map covers captured/imported traffic; cURL import rejects unsupported options and file uploads.

Linked issues

These feature scopes are implemented in this PR and remain open pending merge.

Closes #2
Closes #3
Closes #4
Closes #5
Closes #6
Closes #7
Closes #8
Closes #9
Closes #10

Contribution workflow

Added CONTRIBUTING.md, GitHub bug/feature issue forms, a PR template, and a read-only GitHub Actions workflow running syntax checks and the Node regressions. YAML and template/workflow structures validated locally; all 29 tests and syntax checks passed. Browser behavior is unchanged by this contribution-workflow commit.

GitHub Actions validation on Node 22 also passed: https://github.com/user-github-me/interceptor/actions/runs/37097320891. All eight feature/community issues are linked as closing references and remain open pending merge.

Platform shortcuts

Issue #10: Intercept/Repeater/Decoder/tool-switcher hints and button tooltips show Command on macOS and Ctrl on Windows/Linux, with matching accessible keyboard metadata. Browser platform API detection has a local fallback; Ctrl and Command handlers remain working. The Decoder icon uses a neutral symbol. Real-browser tests verify OS-specific rendering, tooltips, ARIA and both tool-switcher bindings; all existing integration scenarios still pass.

@user-github-me
user-github-me merged commit eeb6500 into main Oct 3, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment