codekingpro/portable-devtools
115k
1from collections.abc import Sequence2from typing import Optional3 4from mitmproxy import optmanager5 6CONF_DIR = "~/.mitmproxy"7CONF_BASENAME = "mitmproxy"8CONTENT_VIEW_LINES_CUTOFF = 5129KEY_SIZE = 204810 11 12class Options(optmanager.OptManager):13 def __init__(self, **kwargs) -> None:14 super().__init__()15 self.add_option(16 "server", bool, True, "Start a proxy server. Enabled by default."17 )18 self.add_option(19 "showhost",20 bool,21 False,22 """Use the Host header to construct URLs for display.23 24 This option is disabled by default because malicious apps may send misleading host headers to evade25 your analysis. If this is not a concern, enable this options for better flow display.""",26 )27 self.add_option(28 "show_ignored_hosts",29 bool,30 False,31 """32 Record ignored flows in the UI even if we do not perform TLS interception.33 This option will keep ignored flows' contents in memory, which can greatly increase memory usage.34 A future release will fix this issue, record ignored flows by default, and remove this option.35 """,36 )37 38 # Proxy options39 self.add_option(40 "add_upstream_certs_to_client_chain",41 bool,42 False,43 """44 Add all certificates of the upstream server to the certificate chain45 that will be served to the proxy client, as extras.46 """,47 )48 self.add_option(49 "confdir",50 str,51 CONF_DIR,52 "Location of the default mitmproxy configuration files.",53 )54 self.add_option(55 "certs",56 Sequence[str],57 [],58 """59 SSL certificates of the form "[domain=]path". The domain may include60 a wildcard, and is equal to "*" if not specified. The file at path61 is a certificate in PEM format. If a private key is included in the62 PEM, it is used, else the default key in the conf dir is used. The63 PEM file should contain the full certificate chain, with the leaf64 certificate as the first entry.65 """,66 )67 self.add_option(68 "cert_passphrase",69 Optional[str],70 None,71 """72 Passphrase for decrypting the private key provided in the --cert option.73 74 Note that passing cert_passphrase on the command line makes your passphrase visible in your system's75 process list. Specify it in config.yaml to avoid this.76 """,77 )78 self.add_option(79 "client_certs", Optional[str], None, "Client certificate file or directory."80 )81 self.add_option(82 "ignore_hosts",83 Sequence[str],84 [],85 """86 Ignore host and forward all traffic without processing it. In87 transparent mode, it is recommended to use an IP address (range),88 not the hostname. In regular mode, only SSL traffic is ignored and89 the hostname should be used. The supplied value is interpreted as a90 regular expression and matched on the ip or the hostname.91 """,92 )93 self.add_option("allow_hosts", Sequence[str], [], "Opposite of --ignore-hosts.")94 self.add_option(95 "listen_host",96 str,97 "",98 "Address to bind proxy server(s) to (may be overridden for individual modes, see `mode`).",99 )100 self.add_option(101 "listen_port",102 Optional[int],103 None,104 "Port to bind proxy server(s) to (may be overridden for individual modes, see `mode`). "105 "By default, the port is mode-specific. The default regular HTTP proxy spawns on port 8080.",106 )107 self.add_option(108 "mode",109 Sequence[str],110 ["regular"],111 """112 The proxy server type(s) to spawn. Can be passed multiple times.113 114 Mitmproxy supports "regular" (HTTP), "local", "transparent", "socks5", "reverse:SPEC",115 "upstream:SPEC", and "wireguard[:PATH]" proxy servers. For reverse and upstream proxy modes, SPEC116 is host specification in the form of "http[s]://host[:port]". For WireGuard mode, PATH may point to117 a file containing key material. If no such file exists, it will be created on startup.118 119 You may append `@listen_port` or `@listen_host:listen_port` to override `listen_host` or `listen_port` for120 a specific proxy mode. Features such as client playback will use the first mode to determine121 which upstream server to use.122 """,123 )124 self.add_option(125 "upstream_cert",126 bool,127 True,128 "Connect to upstream server to look up certificate details.",129 )130 131 self.add_option(132 "http2",133 bool,134 True,135 "Enable/disable HTTP/2 support. HTTP/2 support is enabled by default.",136 )137 self.add_option(138 "http2_ping_keepalive",139 int,140 58,141 """142 Send a PING frame if an HTTP/2 connection is idle for more than143 the specified number of seconds to prevent the remote site from closing it.144 Set to 0 to disable this feature.145 """,146 )147 self.add_option(148 "http3",149 bool,150 True,151 "Enable/disable support for QUIC and HTTP/3. Enabled by default.",152 )153 self.add_option(154 "http_connect_send_host_header",155 bool,156 True,157 "Include host header with CONNECT requests. Enabled by default.",158 )159 self.add_option(160 "websocket",161 bool,162 True,163 "Enable/disable WebSocket support. "164 "WebSocket support is enabled by default.",165 )166 self.add_option(167 "rawtcp",168 bool,169 True,170 "Enable/disable raw TCP connections. "171 "TCP connections are enabled by default. ",172 )173 self.add_option(174 "ssl_insecure",175 bool,176 False,177 """Do not verify upstream server SSL/TLS certificates.178 179 If this option is enabled, certificate validation is skipped and mitmproxy itself will be vulnerable to180 TLS interception.""",181 )182 self.add_option(183 "ssl_verify_upstream_trusted_confdir",184 Optional[str],185 None,186 """187 Path to a directory of trusted CA certificates for upstream server188 verification prepared using the c_rehash tool.189 """,190 )191 self.add_option(192 "ssl_verify_upstream_trusted_ca",193 Optional[str],194 None,195 "Path to a PEM formatted trusted CA certificate.",196 )197 self.add_option(198 "tcp_hosts",199 Sequence[str],200 [],201 """202 Generic TCP SSL proxy mode for all hosts that match the pattern.203 Similar to --ignore-hosts, but SSL connections are intercepted.204 The communication contents are printed to the log in verbose mode.205 """,206 )207 self.add_option(208 "udp_hosts",209 Sequence[str],210 [],211 """212 Generic UDP SSL proxy mode for all hosts that match the pattern.213 Similar to --ignore-hosts, but SSL connections are intercepted.214 The communication contents are printed to the log in verbose mode.215 """,216 )217 self.add_option(218 "content_view_lines_cutoff",219 int,220 CONTENT_VIEW_LINES_CUTOFF,221 """222 Flow content view lines limit. Limit is enabled by default to223 speedup flows browsing.224 """,225 )226 self.add_option(227 "key_size",228 int,229 KEY_SIZE,230 """231 TLS key size for certificates and CA.232 """,233 )234 self.add_option(235 "protobuf_definitions",236 Optional[str],237 None,238 "Path to a .proto file that's used to resolve Protobuf field names when pretty-printing.",239 )240 self.add_option(241 "tcp_timeout",242 int,243 600,244 """245 Timeout in seconds for inactive TCP connections. Connections will be closed after this period of inactivity.246 """,247 )248 249 self.update(**kwargs)250 