Charles – Web Debugging Proxy Application
charlesproxy.com
charlesproxy.com
It's free. It's a breeze to set up, all you need to do is point it at the upstream server you are testing, and it has lua support so you can write code and modify requests on the fly, strip headers, inject things with code.
All the work is already done to manipulate HTTP requests and responses in nginx so it is actually really smooth, there is no learning curve of a new tool, and everything just works.
Do you set up anything to terminate SSL?
http://docs.mitmproxy.org/en/latest/scripting/inlinescripts.... https://github.com/mitmproxy/mitmproxy/tree/master/examples
couple of examples that come to mind:
* Want to test your production/deployed app against a dev/local api server? Have it redirect traffic to a different host and rewrite any headers required (production vs dev api keys for example) - That includes DNS spoofing and re-mapping host names as required.
* Found a bug on a web site and want to test a fix to the javascript without setting up a whole environment? Copy the javascript file in question to your hdd, modify it as desired and have Charles serve that file up when the browser/app requests the original
I don't have any connection to the author; just been well worth its price for me.
The only thing that really annoys me is that, this being a Java app, the interface works slightly different than the standard OS X interface I'm using to.
I regularly use cmd + backspace, for example, to delete all text until between the beginning of the line and the cursor. In Charles this is a hot key that removes all recorded requests. There are more of such things.
I've been looking for a similar app with a native UI, but haven't been able to find one yet.
Disclosure: I'm the developer.
I should update already ;)
That didn't stop them from expecting me to diagnose what was wrong with their custom app. When I noticed that I also could submit test data to a test store in the app on my iPhone (it was an exclusively mobile only app) I ran the app through Charles and discovered that the app was spitting back a SQL Server error - that the disk was full.
48 hours later and the so called database gurus in South Africa had fixed the issue. I would be prevented Dom gaining access to these critical systems throughout my time at that company.
In the technical groups, Charles can usually be bettered for ease of use by custom tools for specific use cases. It is pretty quick and easy to use the proxy libraries in Node.js to throw together internal tools with a command line interface, for example.
Why does team must-do-everything-in-the-terminal always come off as so religiously provocative and desperate? Not everyone is obsessed with their keyboard and feel like going through a huge learning curve to use basic tools, most of us prefer utilizing the mouse and GUIs.
People would have less problem if the submitted was an open source tool, GUI or not.
P.S. Terminal application does have tremendous advantage when you work on a headless server. I used mitmproxy and it's great. The ncurse'd interface isn't harder to use than that of a GUI.
I love MITMproxy and use it several times a day, but it is a bit to hard for newcomers go get their head around.
I also post a lot of different things to HN as long as I love it myself ;)
Plus, the Charles icon on Mac is always an idiosyncratic delight to see in the dock.
Wireshark is also great but has a steep learning curve.
The point and click scripting it does is pretty neat. Makes it easy to stub out responses if you happen to be a client developer blocked by your server developers.
It's very powerful, but unfortunately it just caused the first mobile I tried to misbehave, I'm assuming because the certificate was pinned.
I can't use Charles at all in Firefox.
I've used the nagware version at work while waiting for purchasing approval. It's perfectly functional for the work I do, and only very slightly annoying. YMMV depending on your needs (I never need it for more than ten minutes at a time).
I prefer using MITMproxy/dump together with Node but this is a lot more simpler tool to get your head around.