Skip to content

Releases: hkiam/quena

Quena v0.1.5

Choose a tag to compare

@github-actions github-actions released this 03 Oct 17:22

Changed

  • Inspector views in two levels: each request and response card first offers the
    sections Headers, Body, Cookies, Auth and Raw (with the number of headers and
    cookies, and a dot for authentication), then, below them, only the body views that fit
    the content, the best one first. For example, Formatted · Tree · Plain Text for JSON and
    SOAP · Formatted · Tree · Plain Text for SOAP. Views that do not fit stay reachable under
    Other. Alt 1…Alt 5 pick the section, Alt ←/→ the view. The single row of all views
    is still available: Settings → General → Inspector views → Flat.

  • New installations start in the Quena layout with the request above the response; the
    layout choice on first start is gone. Settings → General → Layout and
    View → Request Beside Response still switch. Existing layouts are kept.

  • No browser menu on right-click any more (Reload, Inspect Element …). Text fields and
    editors get an Edit menu (Undo, Redo, Cut, Copy, Paste, Select All), selected text a Copy
    menu, and places without a sensible menu none. In release builds the developer tools are
    off, and on Windows WebView2's own menus too (this also covers the HTML preview). The
    Developer menu (mock data, Reload UI) is only in debug builds; Performance Overlay
    moved to View.

  • Context menus in the inspector: copy header values, table rows, JSON values with their
    JSONPath, XML elements with their XPath, WebSocket messages and SSE events; copy or save
    bodies and multipart parts; expand or collapse trees. From the JSON tree a value can be
    changed or removed, or a broken element appended to a list, in later messages of the
    same URL (a rewrite rule).

  • More context menus: below the sessions (open archive, save all, select all, remove
    all), on timeline rows (inspect, copy URL, remove from the timeline, the selection's menu),
    on navigator entries (show only, select their sessions), on diagnostic findings
    (select affected sessions, copy), log lines and statistics.

  • Navigator left of the session list (off by default; toolbar button, View → Navigator,
    Ctrl/⌘ Alt N): the groups of the sessions (connection, host, process, trace id,
    session cookie, Custom) or the host/path structure, with counts and errors. A click
    narrows the list to that group or path, on top of the filters; a bar above the list
    shows it and brings everything back. Structure moved from the right pane into the
    navigator; there a click now narrows the list instead of selecting (right-click →
    Select These Sessions). It opens with the structure until the list is grouped; while
    it is open, the list's Group column starts narrower.

  • README and manual screenshots retaken with the new defaults, plus one of the navigator.

Fixed

  • A plain XML document sent as text/xml or application/xml no longer opens in the SOAP
    view, and is no longer offered the SOAP and Atom/OData views. Quena now checks the root
    element of the decoded body (SOAP envelope, Atom feed or entry, OData metadata) instead
    of trusting the content type. JSON and XML with a wrong or missing content type get the
    matching views.
  • The session count of a list group no longer overlaps the group's name.
  • A saved layout without a preset (e.g. only a theme set by hand) opened with the Classic
    columns; it now gets the Quena layout.

Quena v0.1.4

Choose a tag to compare

@github-actions github-actions released this 03 Oct 08:39

Added

  • MCP server for AI agents (Options → AI agents (MCP)): Claude Code and other MCP
    clients connect over Streamable HTTP on 127.0.0.1 with a bearer token. They list,
    search and read sessions and bodies (decoded, paged, size-limited), and see statistics,
    mock rules and breakpoints. With full control they also start and stop capturing,
    remove sessions, send and replay requests, edit mock rules, set breakpoints, release
    paused sessions and export archives. The server is off by default, runs apart from the
    proxy and rejects other Host/Origin names (DNS rebinding). Captured credentials,
    tokens and secret values are replaced before an agent sees them (unless allowed), and
    agents read and write files only in one folder (Folder for agent files).
  • Rewrite rules: change real requests and responses on their way — JSON values by
    JSONPath (set, remove, append; append to every list, with a broken copy of the first
    element by default), regex replacements, headers and status, filtered by match pattern,
    status and content type. Set up by agents over MCP (with a dry run on a captured session)
    and listed in the Mock Rules tab; the status bar shows when they are active. Without
    rules the forwarding path is unchanged; header and status changes never hold a body
    back; body changes hold back only matching bodies (JSON by default) up to 4 MB
    (at most 16 MB; 256 MB for all held-back bodies together) and 30 s and otherwise
    forward them unchanged as they stream, decode gzip/br/zstd, keep
    charset and JSON key order, and leave event streams, JSON lines, partial content and
    binary bodies alone.
  • Grouping in the session list (Group by in the heading's context menu and the command
    palette): by client connection (keep-alive, HTTP/2), host, process, trace or correlation
    id (traceparent, B3, Jaeger, X-Ray, X-Correlation-ID …), session cookie (shown as name
    and hash, never the value) or the Custom column. Groups keep the order of their first
    session and are sorted inside by the chosen column; they can be collapsed and expanded
    (click ▾/▸, ←/→, all at once) and selected as a whole; live traffic joins its group.
    New filter fields conn, trace and session. Connection ids no longer start at 1 on
    every run, so a recovered capture and new traffic never share one.
  • Request collections (.http) in the format of the JetBrains HTTP Client and the VS
    Code REST Client: file variables, environments from http-client.env.json and
    http-client.private.env.json (with $shared), dynamic values ($uuid, $timestamp,
    $randomInt, $processEnv …) and file bodies. Agents list and run them over MCP and
    write captured sessions as a collection; quena-cli http run runs them headless (exit
    code 1 on failures, --save for a HAR/SAZ of the run), quena-cli http from-har writes
    one from captures. The requests appear in the capture, and rules apply.

Fixed

  • Automatic authentication no longer hangs for a minute over a VPN: with a Kerberos
    ticket but no reachable KDC, Negotiate blocked each request until the library gave up.
    Now each step of the Kerberos/SSPI library is cut off after 5 s (Quena falls back to the
    next scheme and skips Negotiate for that host for 10 minutes), and IP addresses and
    localhost never try Kerberos.

Changed

  • Buffering a message for a body rule no longer shows it as paused at a breakpoint.
  • JSON written by quena-cli (sanitized archives, mocks) keeps the key order of
    the source instead of sorting keys, as the app already did.

Quena v0.1.3

Choose a tag to compare

@github-actions github-actions released this 01 Oct 15:08

Added

  • Sanitized export for sharing (File → Export Sessions → Sanitized for Sharing): a
    SAZ/HAR copy for vendors or support. The Support preset replaces credentials, tokens,
    secret URL parameters, secret body fields, e-mail addresses, IBANs and card numbers (check
    digits); GDPR strict also replaces phone numbers, IP addresses, personal fields, tax and
    social security numbers and process names, and cuts bodies. Deterministic and local (no
    AI), structure-preserving for JSON, forms, multipart, XML, HTML, SSE and WebSocket
    messages, stable pseudonyms (<email-3>), bodies keep/cut/placeholder, own names and
    patterns; a redaction log is shown and stored in the archive (QUENA-REDACTION.txt, HAR
    log.comment). Names are read as words (apiKey, X-Api-Key, otpCode are secrets,
    passenger or token_type are not; weak names like key/code only with a
    credential-like value); YAML, JavaScript, CSS, GraphQL and other text is scanned for
    name: value pairs, credentials and URLs; compressed and fragmented WebSocket messages,
    path tokens, signed-URL parameters and user headers are covered; hosts stay, IP literals
    go with the IP option. From the session list's context menu it exports the right-clicked
    sessions, even a single one; the dialog shows the scope and switches between the
    selection and all sessions, checks own patterns before the file is chosen (an error
    keeps the entries), and never replaces another open dialog with the redaction log (the
    status bar offers Show redaction log instead).
  • Mocks from a capture (Mocks from Sessions…, Create from sessions… in Mock Rules,
    the command palette; File → Export Sessions → Mocks… starts with the package): recorded
    sessions become Mock Rules at once, a shareable .quena-mocks package (import in Mock
    Rules, also by drag and drop), or a WireMock export (mappings, __files, scenarios for
    sequences). Options for hosts, static resources, ignored query parameters, responses in
    recorded order, body matching, latency, preflights, error responses and sanitizing.
    Package chips show the hosts and offer Reset sequences; package names are lower case.
    An imported package may only answer from its own files or with *<status>, *delay: (at
    most 60 s), *drop, *reset and *CORSPreflightAllow, and each rule must be limited to
    a host; other rules are left out and counted. A WireMock folder export replaces its
    mappings/, __files/ and README.md (no stale mappings); ZIPs and packages are written
    atomically. 204/304 mocks carry no body.
  • Mock Rules match request bodies as JSON (BODYJSON:), GraphQL operations (GRAPHQL:,
    optionally by queryHash) and by SHA-256 (BODYHASH:); URLWithBody: compares the
    decoded body. .farx export leaves out match once chains (with a note in the file).
  • quena-cli sanitize and quena-cli mock: config files are read strictly (unknown keys
    are named, exit 2; sanitize --config also takes the app's saved options), no output may
    overwrite a capture or another output, --package must end in .quena-mocks, a
    --wiremock folder may not be an existing file, and --timeout also covers sanitizing
    and building the mocks (exit 3).
  • Diagnostics in CI: quena-cli, a command line program without a window, runs the
    diagnostics on HAR/SAZ files (e.g. recorded by Playwright or Cypress tests) and turns the
    report into a quality gate: --fail-on, comparison with a --baseline report (only new or
    more severe findings count), metric budgets (--budget requests=+10%), --ignore, a
    settings file, output as Markdown, JSON, JUnit XML and GitHub annotations, exit codes for
    CI. Ships as archives for Windows, macOS and Linux (x64/arm64), as a GitHub Action
    (hkiam/quena/diagnose) and as a Docker image (ghcr.io/hkiam/quena-cli); examples for
    Playwright and Cypress, manual page Diagnostics in CI.
  • Diagnostics: OAuth 2.0 / OpenID Connect rules (OAUTH-ERROR, OAUTH-FLOW,
    TOKEN-EXPIRED, TOKEN-NOTYET, TOKEN-AUDIENCE, TOKEN-SCOPE, TOKEN-SIZE,
    TOKEN-IN-URL, TOKEN-REFRESH, OIDC-LOOP, OIDC-SILENT, OIDC-DISCOVERY). A built-in
    knowledge base recognises Microsoft Entra ID (incl. B2C and External ID), Keycloak, Okta,
    Auth0, Amazon Cognito, Google, AD FS, Duende IdentityServer and PingFederate, explains
    their error codes (e.g. AADSTS50011, Keycloak's “Session not active”) and names the place
    in the admin UI where the cause is fixed — in English and German.
  • Analyzer plugins receive authentication facts: the non-secret claims of JWTs sent as
    bearer tokens, the parameters of OAuth authorization and token requests, OAuth error
    responses and OpenID discovery documents (auth in the analyzer contract). Secrets,
    signatures and personal claims never leave the host.

Changed

  • Diagnostics: repeated token requests are reported as TOKEN-REFRESH (previously part of
    AUTH-REPEAT); sign-in loops, OAuth errors and the requests of a sign-in loop are no longer
    repeated as REDIRECT, AUTH-FAIL, ERR-HTTP or DUP-EXACT; AUTH-FAIL shows the
    WWW-Authenticate error of an API.
  • Redaction for analyzer plugins keeps the non-secret OAuth parameters of URLs
    (client_id, response_type, scope, prompt …; redirect_uri without query and user
    info) and the error, error_description, realm and scope values of
    WWW-Authenticate; code_challenge, code_verifier and login_hint are now redacted.
  • Timeline: long pauses without traffic (e.g. sessions of two captures a day apart) are
    collapsed to a narrow break labelled with their length, and every block of traffic starts
    with its clock time; Collapse pauses switches back to the real scale. Axis labels never
    overlap.
  • Timeline: a time axis with grid lines; zoom with Ctrl/⌘ + wheel (or pinch) around the
    pointer, or with the zoom buttons and Fit; columns (#, method, status, URL, duration,
    size, graph) can be moved, resized and shown or hidden (right-click the header), and the
    columns left of the graph stay in place while it scrolls; scrollbars appear when needed.
    A click focuses a session without changing the selection, a double-click opens it in
    Inspect.
  • Removing sessions (Del / Backspace, Shift+Del, Ctrl+X, toolbar, menus) asks for
    confirmation first; Enter confirms, Esc cancels.

Fixed

  • Mock Rules: METHOD: combined with URLWithBody: never matched, because the request body
    was not buffered for the inner pattern.
  • Timeline: the session that ends last was cut off at the right edge, and long time spans
    were labelled in thousands of seconds; the axis now uses clock units (ms, s, min, h, d) and
    shows the date when the sessions span more than a day.
  • Removed sessions stayed in the list (the status bar showed “4 of 3 sessions”) until
    something else changed it, so Del seemed to do nothing.

Quena v0.1.2

Choose a tag to compare

@github-actions github-actions released this 30 Sep 16:50

Diagnostics, a German user interface and correct character encodings everywhere — plus the
fixes of a thorough review (including a security fix for Copy as PowerShell/cURL).
Packages are still not signed with a paid certificate (see the notes for 0.1.0).

  • Diagnostics turns a capture into a short list of prioritised findings with evidence:
    performance, duplicates and N+1, errors and authentication, character encodings, clocks,
    and how sensitive each operation is to slow networks.
  • German user interface, including the menus (Settings → General → Language).
  • Character encodings: every view shows bodies in their real charset, with an override.
  • Map Remote / Map Local, drag & drop of archives, a timing waterfall, a host/path tree,
    a theme choice, and a user manual.
  • macOS: one universal .dmg; Windows: installer (.exe / .msi) or the portable
    Quena_0.1.2_x64-portable.zip; Linux: .deb, .rpm and AppImage for x86_64 and arm64.

Added

  • Character encodings: every text view decodes bodies in their real charset (BOM, then the
    Content-Type charset, then <?xml encoding> / HTML <meta>, then the type's default) and
    shows it ("windows-1252 · header") with a menu to view the body in another charset. UTF-16
    bodies are formatted too; multipart parts and form data use their own charset; RFC 8187
    filename*= parameters are shown decoded.
  • Diagnostics finds encoding problems: a declared charset that does not match the bytes
    (“Grüße” → “Gr��e” or “Grüße”), header, BOM and document declaration that disagree, text
    without any charset, double-encoded UTF-8, characters already lost (�), JSON not in UTF-8,
    unknown charset names, NUL bytes in text, and compressed data without (or with a broken)
    Content-Encoding.
  • Diagnostics finds clock problems from the Date header: a server whose clock differs from
    this computer (critical from 5 minutes, Kerberos' tolerance), this computer's own clock
    being off (several unrelated sites agree), and servers behind one name with different
    clocks.
  • Diagnostics (View → Diagnostics, bundled plugin webdiag): turns a capture into a short
    list of prioritised findings with evidence instead of thousands of sessions — slow requests
    and server time, large and uncompressed transfers, exact and semantic duplicates (OData
    aware), N+1 and polling patterns, retries and double submits, HTTP errors and connection
    failures, authentication loops and repeated NTLM/Kerberos handshakes, redirect chains, cookie
    and caching problems, connection reuse, old TLS, CORS preflights, unbounded OData queries,
    and how sensitive each operation is to latency and bandwidth (estimates per network
    profile, clearly marked). Profiles: full, performance, troubleshooting, authentication,
    network resilience, modernization. Scope: visible or selected sessions, narrowed to
    processes or target hosts; mixed traffic of several applications is pointed out. Findings
    select their sessions with one click. Reports save as JSON or Markdown, copy as a prompt for
    an AI assistant (redacted), and compare with a saved report. Everything runs locally; tokens
    and cookie values never reach the plugin.
  • Plugin API: analyzer plugins analyse a whole capture (contract in
    plugins/webdiag/REPORT.md).
  • Inspectors remember the chosen view per kind of content, separately for request and
    response (e.g. SOAP → XML, JSON → Body, Fast Infoset → its plugin view). Until a view was
    chosen, the one that fits the content opens (SOAP, gRPC, WebSocket, images, form data …).
    On by default; Settings → General → Inspector views turns it off or forgets the choices.
  • JWT plugin: decodes JSON Web Tokens in Authorization/Proxy-Authorization (Bearer, DPoP),
    cookies, Set-Cookie and common token headers: header (alg, typ, kid …), claims with the
    registered ones explained, exp/nbf/iat as dates with "expired 3 h ago" / "valid for
    12 min", and the signature algorithm (not verified). Encrypted tokens (JWE) show their header.
    Shown in the Auth view next to Kerberos/NTLM (no extra tab); the Auth view now also lists
    tokens a plugin recognises in cookies and token headers.
  • GraphQL plugin: requests (application/graphql or JSON with query/variables/
    operationName, batches, persisted queries) with the operation and the query pretty-printed,
    and GraphQL JSON responses with the errors first.
  • Drop .saz or .har archives onto the window to load them.
  • Timeline shows a waterfall: request, DNS, connect, TLS, send, wait (time to first byte)
    and receive per session, with the time of each phase in the tooltip.
  • Structure tab: the visible sessions as a tree of hosts and paths with counts and errors;
    clicking a host or folder selects its sessions.
  • German user interface, including the native menus: Settings → General → Language (like
    the system, English, Deutsch). Numbers and sizes follow the language (1.234, 1,5 KB).
  • Theme choice in Settings → General: like the system, light or dark.
  • Slow and large responses stand out in the session list: duration over 1 s / 5 s and body
    size over 1 MB / 10 MB are shown in amber / red.
  • Copy as fetch (JavaScript), PowerShell (Invoke-WebRequest) and Python requests, next
    to cURL.
  • Map Remote: Mock Rules → Add mapping… → Map Remote forwards everything under a URL
    prefix to another server (prefix:https://prod…/api/ → https://staging…/api/), keeping
    the rest of the path and the query; the session comment names the original URL.
  • Map Local: Add mapping… → Map Local serves a folder under a URL prefix (dir:/folder
    action): index.html for folders, Content-Type by extension, a clear 404 for missing files;
    paths that would leave the folder (.., encoded %2e%2e, symlinks outside) are refused.
  • Mock Rules match prefix: for URLs that start with a given text.
  • User manual at https://hkiam.github.io/quena/ (MkDocs Material, sources in manual/):
    installation, capturing, HTTPS and devices, the session list, inspectors, Mock Rules,
    analysis, archives, scripting, authentication, plugins, settings, shortcuts and
    troubleshooting; built by the Manual workflow and published to GitHub Pages.

Changed

  • The right pane's tabs show icons only when their names do not fit the pane.
  • The command palette also finds commands by their English names.
  • Inspector view tabs show as many views as fit the width; More only holds the ones that do
    not fit, and the views are ordered by how well they fit the content.

Fixed

  • Diagnostics and header inspectors (JWT, Kerberos/NTLM) opened right after start said no
    plugin was installed while the plugins were still being compiled; they now show that
    plugins are loading and update when they are ready.
  • Umlauts and other non-ASCII characters were shown as � in inspector bodies (and in JSON,
    XML, SOAP, multipart, form data, the large-text view) when a body was not UTF-8; search
    did not find them either.
  • Composer and breakpoint edits keep the body's charset (unedited bodies are sent byte for
    byte); Copy as sends exactly the recorded bytes for bodies that are not UTF-8.
  • HAR import: a leftover Content-Encoding on a request whose text is already decoded is
    dropped, so it is no longer reported as undecodable.
  • Plugins dialog: long "Applies to" lists squeezed the other columns to single characters;
    the columns keep their width, the Diagnostics plugin shows what it applies to, and status
    and column titles are translated.
  • Inspector view tabs overflowed (and hid the pane titles) after coming back to Inspect
    from another right-pane tab; they are measured again when the view shows.
  • Diagnostics:
    • A single sign-on round trip is no longer reported as a redirect loop.
    • Polling during an outage is no longer a "retry storm".
    • Data timestamps are no longer dropped as cache busters.
    • Requests still open at capture end are neither failures nor sequential chains.
    • A session-wide correlation id no longer merges separate actions.
    • Transfer-time estimates agree between rules and include packet loss.
    • Slow critical endpoints are never cut from the list.
    • Large captures stay fast (500 000 sessions in about 2 s); the authentication check is
      linear.
    • A cancelled or older run can no longer replace a newer report, and "Remove all" clears
      the report.
  • Diagnostics tab:
    • It keeps the chosen finding and a running analysis across tab switches.
    • It notices enabled or disabled plugins.
    • Filters are reset for a new report.
    • Markdown exports escape text from the traffic.
  • Structure: the "(this path)" row selects exactly that path; all open levels refresh in
    one pass and less often.
  • Map Local serves large files without blocking the proxy and answers 500 instead of a
    truncated file when reading fails.
  • Dropped archives: temporary copies are removed even when an import fails or is
    cancelled, left-overs at startup; drops are limited to 8 GiB and need free disk space.
  • GraphQL formatting stops at a size limit instead of growing without bound; JWT dates given
    in milliseconds are recognised.
  • Language switch: nothing changes when the choice cannot be saved; Exit is translated.

Security

  • Copy as PowerShell / cURL: a crafted HTTP method or typographic quotes in a header or
    body could make the pasted command run other programs. Methods are quoted
    (-CustomMethod for non-standard ones), all PowerShell quote characters escaped, control
    characters written explicitly; duplicate header names are merged.
  • Map Local verifies the opened file itself (no symlink swap between check and open), and
    prefix: rules that name only an origin no longer match look-alike hosts or other ports
    (https://prod.example.com ≠ `https:...
Read more

Quena v0.1.1

Choose a tag to compare

@github-actions github-actions released this 30 Sep 07:14

Faster start and capture switching, more platforms, and more robustness. Packages are still
not signed with a paid certificate (see the notes for 0.1.0).

  • macOS: one universal .dmg for Apple Silicon and Intel.
  • Windows: installer (.exe / .msi) or the portable Quena_0.1.1_x64-portable.zip.
  • Linux: .deb, .rpm and AppImage for x86_64 and arm64.

Added

  • macOS builds are universal (Apple Silicon and Intel); Linux packages for arm64 (aarch64)
    in addition to x86_64.
  • UI end-to-end tests that start the real app and drive it through WebDriver (Linux, in CI).
  • Requests the HTTP parser rejects (malformed request line or headers, too large heads) appear
    as aborted sessions with the raw bytes received, instead of only a 400 to the client.

Changed

  • Layout uses the whole window at every size: the Path column of the session list takes the
    width left over by the other columns; in a narrow right pane request and response go above
    each other automatically and the pane's tabs show icons only; toolbars in the inspectors wrap
    instead of cutting off buttons; splitters keep a usable minimum size for every area.
  • The capture switch reacts immediately and shows "Starting…"/"Stopping…" while the system
    proxy is being changed.
  • Stopping the capture also closes open client connections, tunnels and WebSockets (after the
    request in flight), so nothing more is recorded.
  • WebSocket over HTTP/2 (RFC 8441) is no longer offered to browsers; they open WebSockets on a
    separate HTTP/1.1 connection, which Quena records frame by frame.
  • Faster start: the window no longer waits for the capture to start (setting the system proxy,
    loading a PAC file), for plugins to compile or for the OS root certificates to load. Plugins
    are compiled once and cached (plugin-cache in the data folder); the UI's startup bundle is
    60 % smaller (editors, diff view and the QR code load on first use).
  • Starting and stopping the capture on macOS changes all network services at once instead of
    one after another (several times faster on Macs with many network services).
  • Portable mode (a portable file or quena-data folder beside the executable, on every
    platform) now keeps the web view's cache and storage in quena-data as well, and bundled
    plugins are found in a plugins folder next to the executable.

Fixed

  • Body views of small responses left a white area below the text (the editor did not fill
    the pane when no notice was shown above it).
  • Mock Rules: the Latency and Hits column headings broke in the middle of the word.
  • Windows: logging off or shutting down while Quena runs restores the system proxy (it could
    stay pointed at Quena until the next start, leaving the user without internet).
  • Starting the capture at launch and toggling it at the same moment could start it twice.

Quena v0.1.0

Choose a tag to compare

@github-actions github-actions released this 29 Sep 15:16

First public release of Quena, a local HTTP(S) debugging proxy for macOS, Windows and Linux:
capture, inspect, change and replay HTTP/1.1, HTTP/2, HTTPS, WebSocket and SSE traffic, with
mock rules, breakpoints, a composer, JavaScript rules, WebAssembly plugins, automatic
authentication (NTLM, Kerberos, Basic) and SAZ/HAR import and export.

Installing: packages are not signed with a paid certificate or notarized yet.

  • macOS (.dmg, Apple Silicon): on first start macOS warns about an unidentified developer —
    open System Settings → Privacy & Security and choose Open Anyway.
  • Windows (.exe / .msi): SmartScreen may warn — More info → Run anyway.
  • Windows portable (Quena_0.1.0_x64-portable.zip, xcopy deployment): unzip anywhere and
    start Quena.exe — no installation; settings, sessions and the root certificate stay in
    quena-data beside it (see README-portable.txt).
  • Linux: .deb (Debian, Ubuntu), .rpm (Fedora, openSUSE) or the AppImage (x86_64).

This is an early 0.x release: settings, file formats and the plugin API may still change.

Added

  • Linux support on par with macOS and Windows: system proxy for GNOME and KDE Plasma (restored
    on quit and after a crash), root certificate trust for Chrome/Firefox (NSS) and the system
    store (via pkexec), process attribution via /proc, credentials in the Secret Service
    keyring, Kerberos single sign-on via GSSAPI (loaded at runtime), xdg-open/file manager
    integration. Packages: .deb, .rpm, AppImage; built and tested in CI on Ubuntu 22.04.
  • Double-clicked or "Open With" .har/.saz files are loaded (all platforms).
  • tools/linux/Dockerfile: the Linux build and test environment.
  • Hardening against broken and hostile traffic: timeouts for stalled clients and servers
    (request head, TLS handshake, DNS, upstream CONNECT, response head, idle tunnels and
    WebSockets), limits for concurrent connections, buffered bodies, decompression, imports and
    inspectors, refusal of request loops into Quena itself, bounded PAC evaluation and download.
    Damaged settings, rules, root certificate, database rows and system-proxy backups no longer
    block the start or lose data; a failing view shows an error instead of a blank window.
  • New app icon.
  • Header inspector plugins: the plugin API gains an additive header-plugin world (existing
    decoder plugins keep working). The bundled auth-tokens plugin decodes SPNEGO, Kerberos
    (AP-REQ/AP-REP/KRB-ERROR) and NTLM Type 1/2/3 tokens in the Auth inspector and flags
    Negotiate that fell back to NTLM. (Marian Gavalier)
  • Ctrl/⌘ +/-/0 zoom the whole UI; cargo build --profile local for fast optimized
    local builds. (Marian Gavalier)

Changed

  • Own default layout: session list left, request and response side by side, rows coloured by
    outcome (5xx red, 4xx amber, redirects muted). The dense stacked arrangement is available as
    the Classic layout (first start, Settings → General).
  • Own look: SVG icons (Lucide), a capture switch, method and status badges in the session list,
    a state bar for in-flight/paused/mocked sessions, tunnels shown by target host with a badge.
  • Command field in the toolbar (Alt+Q) replaces the bar below the list; new command palette
    (Ctrl/⌘ K) with every menu command.
  • Inspectors: request and response cards with segmented tabs (Headers, Body, Cookies, Raw and
    content-specific views), the rest under More; headers as a filterable table in wire order
    with topic tags and optional A–Z sorting.
  • Menus: File, Edit, Capture, View, Tools, Help; breakpoints, mock rules, rules script and
    authentication are under Capture, the Hide … items under View → Hide in List.
  • Own names: Mock Rules, Text Tools, Inspect; inspector tabs Plain Text, Body,
    Form Data, Hex, Image, Preview, Encoding; Rules Script…; Replay …. Filter/command syntax
    and shortcuts are unchanged. Help → Coming from Fiddler Classic… maps the names.
  • .saz is registered as a viewer (macOS rank "Alternate") and not at all on Windows, so Quena
    never takes over another application's file association.

Fixed

  • Automatic authentication falls back to the next offered scheme when the server rejects one
    (e.g. Negotiate advertised but only NTLM working).
  • NTLM no longer uploads the request body twice (the Type 1 leg now goes without it).
  • Plugin call timeout follows wall-clock time on loaded machines.
  • Sorting 500k sessions by host no longer allocates per comparison (several times faster on
    Windows).
  • Request bodies could go missing when a response finished before its request body was
    recorded (both are now recorded in order, and a session is saved only when all its bodies are).
  • Sessions whose client disconnected stayed "in flight" forever; they now end as aborted.
  • Windows: Ctrl+F opened the web view's page search instead of Find Sessions; browser
    shortcuts (Ctrl+R, F5, Ctrl+P) no longer reach the web view.
  • macOS: downloaded builds were reported as "damaged" (incomplete signature); the bundle is now
    signed ad hoc, with the JIT permission the plugin engine needs.
  • Tab strips in Settings, Composer and Connect Device had no spacing between titles.
  • Raw inspector uses the whole pane; larger base text size (13 px). Documented toolchain
    minimums corrected (Rust 1.95, Node.js 20.19+/22.12+). (Marian Gavalier)