Skip to main content

Module session_import

Module session_import 

Source
Expand description

Web-session capture parsers (Phase 24.5, step 3).

One implementation, in vault-core: the app reaches it over IPC and the CLI calls it directly, the pools.ts shape, so a paste that imports one way in the window cannot import another way from the terminal.

Inputs: DevTools Copy as cURL (bash, cmd and PowerShell), HAR, Set-Cookie lines, and a Firefox cookies.sqlite. Everything parsed is attacker-controlled text (a pasted file from a site you were logged into), so nothing is executed or fetched, lengths are bounded, and cookie values are checked against RFC 6265’s cookie-octet set (S10).

What a capture is not: a place for other credentials. A cURL or HAR paste carries an Authorization header and cookies for CDNs and trackers; S12 says only the chosen origin’s survive and the caller is told what was dropped, by name and never by value.

Structs§

Capture
Cookie

Constants§

CHROME_REFUSAL
What to say when someone asks for Chrome.
MAX_INPUT
Hard cap on pasted input. A HAR of a long session is megabytes; anything past this is not a login capture.

Functions§

detect
Sniffs which dialect a paste is.
parse_auto
Parse a paste of unknown dialect.
parse_curl
DevTools Copy as cURL, bash or cmd flavour.
parse_har
Parses a HAR in memory and keeps only the chosen origin’s request cookies and headers. The HAR itself is never stored: it holds every other site the browser talked to. With several origins and no origin, the error lists them so the caller can ask.
parse_powershell
DevTools Copy as PowerShell (Invoke-WebRequest).
parse_set_cookie
One or more Set-Cookie: lines (or bare name=value; Attr lines).
read_firefox
Reads a Firefox profile’s cookies.sqlite for one host (matching host and its subdomains). Opened read-only from a copy (Firefox keeps the live file locked and its WAL separate). Firefox does not encrypt this file.