Expand description
Web-session capture parsers (Phase 24.5, step 3).
One implementation, in vault-core: the app reaches it over IPC and the CLI
calls it directly, the pools.ts shape, so a paste that imports one way in
the window cannot import another way from the terminal.
Inputs: DevTools Copy as cURL (bash, cmd and PowerShell), HAR,
Set-Cookie lines, and a Firefox cookies.sqlite. Everything parsed is
attacker-controlled text (a pasted file from a site you were logged into), so
nothing is executed or fetched, lengths are bounded, and cookie values are
checked against RFC 6265’s cookie-octet set (S10).
What a capture is not: a place for other credentials. A cURL or HAR paste
carries an Authorization header and cookies for CDNs and trackers; S12 says
only the chosen origin’s survive and the caller is told what was dropped, by
name and never by value.
Structs§
Constants§
- CHROME_
REFUSAL - What to say when someone asks for Chrome.
- MAX_
INPUT - Hard cap on pasted input. A HAR of a long session is megabytes; anything past this is not a login capture.
Functions§
- detect
- Sniffs which dialect a paste is.
- parse_
auto - Parse a paste of unknown dialect.
- parse_
curl - DevTools Copy as cURL, bash or cmd flavour.
- parse_
har - Parses a HAR in memory and keeps only the chosen origin’s request cookies
and headers. The HAR itself is never stored: it holds every other site the
browser talked to. With several origins and no
origin, the error lists them so the caller can ask. - parse_
powershell - DevTools Copy as PowerShell (
Invoke-WebRequest). - parse_
set_ cookie - One or more
Set-Cookie:lines (or barename=value; Attrlines). - read_
firefox - Reads a Firefox profile’s
cookies.sqlitefor one host (matchinghostand its subdomains). Opened read-only from a copy (Firefox keeps the live file locked and its WAL separate). Firefox does not encrypt this file.