Releases: hkiam/quena
Release list
Quena v0.1.5
Changed
-
Inspector views in two levels: each request and response card first offers the
sections Headers, Body, Cookies, Auth and Raw (with the number of headers and
cookies, and a dot for authentication), then, below them, only the body views that fit
the content, the best one first. For example, Formatted · Tree · Plain Text for JSON and
SOAP · Formatted · Tree · Plain Text for SOAP. Views that do not fit stay reachable under
Other.Alt 1…Alt 5pick the section,Alt ←/→the view. The single row of all views
is still available: Settings → General → Inspector views → Flat. -
New installations start in the Quena layout with the request above the response; the
layout choice on first start is gone. Settings → General → Layout and
View → Request Beside Response still switch. Existing layouts are kept. -
No browser menu on right-click any more (Reload, Inspect Element …). Text fields and
editors get an Edit menu (Undo, Redo, Cut, Copy, Paste, Select All), selected text a Copy
menu, and places without a sensible menu none. In release builds the developer tools are
off, and on Windows WebView2's own menus too (this also covers the HTML preview). The
Developer menu (mock data, Reload UI) is only in debug builds; Performance Overlay
moved to View. -
Context menus in the inspector: copy header values, table rows, JSON values with their
JSONPath, XML elements with their XPath, WebSocket messages and SSE events; copy or save
bodies and multipart parts; expand or collapse trees. From the JSON tree a value can be
changed or removed, or a broken element appended to a list, in later messages of the
same URL (a rewrite rule). -
More context menus: below the sessions (open archive, save all, select all, remove
all), on timeline rows (inspect, copy URL, remove from the timeline, the selection's menu),
on navigator entries (show only, select their sessions), on diagnostic findings
(select affected sessions, copy), log lines and statistics. -
Navigator left of the session list (off by default; toolbar button, View → Navigator,
Ctrl/⌘ Alt N): the groups of the sessions (connection, host, process, trace id,
session cookie, Custom) or the host/path structure, with counts and errors. A click
narrows the list to that group or path, on top of the filters; a bar above the list
shows it and brings everything back. Structure moved from the right pane into the
navigator; there a click now narrows the list instead of selecting (right-click →
Select These Sessions). It opens with the structure until the list is grouped; while
it is open, the list's Group column starts narrower. -
README and manual screenshots retaken with the new defaults, plus one of the navigator.
Fixed
- A plain XML document sent as
text/xmlorapplication/xmlno longer opens in the SOAP
view, and is no longer offered the SOAP and Atom/OData views. Quena now checks the root
element of the decoded body (SOAP envelope, Atom feed or entry, OData metadata) instead
of trusting the content type. JSON and XML with a wrong or missing content type get the
matching views. - The session count of a list group no longer overlaps the group's name.
- A saved layout without a preset (e.g. only a theme set by hand) opened with the Classic
columns; it now gets the Quena layout.
Quena v0.1.4
Added
- MCP server for AI agents (Options → AI agents (MCP)): Claude Code and other MCP
clients connect over Streamable HTTP on127.0.0.1with a bearer token. They list,
search and read sessions and bodies (decoded, paged, size-limited), and see statistics,
mock rules and breakpoints. With full control they also start and stop capturing,
remove sessions, send and replay requests, edit mock rules, set breakpoints, release
paused sessions and export archives. The server is off by default, runs apart from the
proxy and rejects otherHost/Originnames (DNS rebinding). Captured credentials,
tokens and secret values are replaced before an agent sees them (unless allowed), and
agents read and write files only in one folder (Folder for agent files). - Rewrite rules: change real requests and responses on their way — JSON values by
JSONPath (set, remove, append; append to every list, with a broken copy of the first
element by default), regex replacements, headers and status, filtered by match pattern,
status and content type. Set up by agents over MCP (with a dry run on a captured session)
and listed in the Mock Rules tab; the status bar shows when they are active. Without
rules the forwarding path is unchanged; header and status changes never hold a body
back; body changes hold back only matching bodies (JSON by default) up to 4 MB
(at most 16 MB; 256 MB for all held-back bodies together) and 30 s and otherwise
forward them unchanged as they stream, decode gzip/br/zstd, keep
charset and JSON key order, and leave event streams, JSON lines, partial content and
binary bodies alone. - Grouping in the session list (Group by in the heading's context menu and the command
palette): by client connection (keep-alive, HTTP/2), host, process, trace or correlation
id (traceparent, B3, Jaeger, X-Ray,X-Correlation-ID…), session cookie (shown as name
and hash, never the value) or the Custom column. Groups keep the order of their first
session and are sorted inside by the chosen column; they can be collapsed and expanded
(click ▾/▸,←/→, all at once) and selected as a whole; live traffic joins its group.
New filter fieldsconn,traceandsession. Connection ids no longer start at 1 on
every run, so a recovered capture and new traffic never share one. - Request collections (
.http) in the format of the JetBrains HTTP Client and the VS
Code REST Client: file variables, environments fromhttp-client.env.jsonand
http-client.private.env.json(with$shared), dynamic values ($uuid,$timestamp,
$randomInt,$processEnv…) and file bodies. Agents list and run them over MCP and
write captured sessions as a collection;quena-cli http runruns them headless (exit
code 1 on failures,--savefor a HAR/SAZ of the run),quena-cli http from-harwrites
one from captures. The requests appear in the capture, and rules apply.
Fixed
- Automatic authentication no longer hangs for a minute over a VPN: with a Kerberos
ticket but no reachable KDC, Negotiate blocked each request until the library gave up.
Now each step of the Kerberos/SSPI library is cut off after 5 s (Quena falls back to the
next scheme and skips Negotiate for that host for 10 minutes), and IP addresses and
localhostnever try Kerberos.
Changed
- Buffering a message for a body rule no longer shows it as paused at a breakpoint.
- JSON written by
quena-cli(sanitized archives, mocks) keeps the key order of
the source instead of sorting keys, as the app already did.
Quena v0.1.3
Added
- Sanitized export for sharing (File → Export Sessions → Sanitized for Sharing): a
SAZ/HAR copy for vendors or support. The Support preset replaces credentials, tokens,
secret URL parameters, secret body fields, e-mail addresses, IBANs and card numbers (check
digits); GDPR strict also replaces phone numbers, IP addresses, personal fields, tax and
social security numbers and process names, and cuts bodies. Deterministic and local (no
AI), structure-preserving for JSON, forms, multipart, XML, HTML, SSE and WebSocket
messages, stable pseudonyms (<email-3>), bodies keep/cut/placeholder, own names and
patterns; a redaction log is shown and stored in the archive (QUENA-REDACTION.txt, HAR
log.comment). Names are read as words (apiKey,X-Api-Key,otpCodeare secrets,
passengerortoken_typeare not; weak names likekey/codeonly with a
credential-like value); YAML, JavaScript, CSS, GraphQL and other text is scanned for
name: valuepairs, credentials and URLs; compressed and fragmented WebSocket messages,
path tokens, signed-URL parameters and user headers are covered; hosts stay, IP literals
go with the IP option. From the session list's context menu it exports the right-clicked
sessions, even a single one; the dialog shows the scope and switches between the
selection and all sessions, checks own patterns before the file is chosen (an error
keeps the entries), and never replaces another open dialog with the redaction log (the
status bar offers Show redaction log instead). - Mocks from a capture (Mocks from Sessions…, Create from sessions… in Mock Rules,
the command palette; File → Export Sessions → Mocks… starts with the package): recorded
sessions become Mock Rules at once, a shareable.quena-mockspackage (import in Mock
Rules, also by drag and drop), or a WireMock export (mappings,__files, scenarios for
sequences). Options for hosts, static resources, ignored query parameters, responses in
recorded order, body matching, latency, preflights, error responses and sanitizing.
Package chips show the hosts and offer Reset sequences; package names are lower case.
An imported package may only answer from its own files or with*<status>,*delay:(at
most 60 s),*drop,*resetand*CORSPreflightAllow, and each rule must be limited to
a host; other rules are left out and counted. A WireMock folder export replaces its
mappings/,__files/andREADME.md(no stale mappings); ZIPs and packages are written
atomically.204/304mocks carry no body. - Mock Rules match request bodies as JSON (
BODYJSON:), GraphQL operations (GRAPHQL:,
optionally byqueryHash) and by SHA-256 (BODYHASH:);URLWithBody:compares the
decoded body..farxexport leaves out match once chains (with a note in the file). quena-cli sanitizeandquena-cli mock: config files are read strictly (unknown keys
are named, exit 2;sanitize --configalso takes the app's saved options), no output may
overwrite a capture or another output,--packagemust end in.quena-mocks, a
--wiremockfolder may not be an existing file, and--timeoutalso covers sanitizing
and building the mocks (exit 3).- Diagnostics in CI:
quena-cli, a command line program without a window, runs the
diagnostics on HAR/SAZ files (e.g. recorded by Playwright or Cypress tests) and turns the
report into a quality gate:--fail-on, comparison with a--baselinereport (only new or
more severe findings count), metric budgets (--budget requests=+10%),--ignore, a
settings file, output as Markdown, JSON, JUnit XML and GitHub annotations, exit codes for
CI. Ships as archives for Windows, macOS and Linux (x64/arm64), as a GitHub Action
(hkiam/quena/diagnose) and as a Docker image (ghcr.io/hkiam/quena-cli); examples for
Playwright and Cypress, manual page Diagnostics in CI. - Diagnostics: OAuth 2.0 / OpenID Connect rules (
OAUTH-ERROR,OAUTH-FLOW,
TOKEN-EXPIRED,TOKEN-NOTYET,TOKEN-AUDIENCE,TOKEN-SCOPE,TOKEN-SIZE,
TOKEN-IN-URL,TOKEN-REFRESH,OIDC-LOOP,OIDC-SILENT,OIDC-DISCOVERY). A built-in
knowledge base recognises Microsoft Entra ID (incl. B2C and External ID), Keycloak, Okta,
Auth0, Amazon Cognito, Google, AD FS, Duende IdentityServer and PingFederate, explains
their error codes (e.g. AADSTS50011, Keycloak's “Session not active”) and names the place
in the admin UI where the cause is fixed — in English and German. - Analyzer plugins receive authentication facts: the non-secret claims of JWTs sent as
bearer tokens, the parameters of OAuth authorization and token requests, OAuth error
responses and OpenID discovery documents (authin the analyzer contract). Secrets,
signatures and personal claims never leave the host.
Changed
- Diagnostics: repeated token requests are reported as
TOKEN-REFRESH(previously part of
AUTH-REPEAT); sign-in loops, OAuth errors and the requests of a sign-in loop are no longer
repeated asREDIRECT,AUTH-FAIL,ERR-HTTPorDUP-EXACT;AUTH-FAILshows the
WWW-Authenticateerror of an API. - Redaction for analyzer plugins keeps the non-secret OAuth parameters of URLs
(client_id,response_type,scope,prompt…;redirect_uriwithout query and user
info) and theerror,error_description,realmandscopevalues of
WWW-Authenticate;code_challenge,code_verifierandlogin_hintare now redacted. - Timeline: long pauses without traffic (e.g. sessions of two captures a day apart) are
collapsed to a narrow break labelled with their length, and every block of traffic starts
with its clock time; Collapse pauses switches back to the real scale. Axis labels never
overlap. - Timeline: a time axis with grid lines; zoom with Ctrl/⌘ + wheel (or pinch) around the
pointer, or with the zoom buttons and Fit; columns (#, method, status, URL, duration,
size, graph) can be moved, resized and shown or hidden (right-click the header), and the
columns left of the graph stay in place while it scrolls; scrollbars appear when needed.
A click focuses a session without changing the selection, a double-click opens it in
Inspect. - Removing sessions (Del / Backspace, Shift+Del, Ctrl+X, toolbar, menus) asks for
confirmation first; Enter confirms, Esc cancels.
Fixed
- Mock Rules:
METHOD:combined withURLWithBody:never matched, because the request body
was not buffered for the inner pattern. - Timeline: the session that ends last was cut off at the right edge, and long time spans
were labelled in thousands of seconds; the axis now uses clock units (ms, s, min, h, d) and
shows the date when the sessions span more than a day. - Removed sessions stayed in the list (the status bar showed “4 of 3 sessions”) until
something else changed it, so Del seemed to do nothing.
Quena v0.1.2
Diagnostics, a German user interface and correct character encodings everywhere — plus the
fixes of a thorough review (including a security fix for Copy as PowerShell/cURL).
Packages are still not signed with a paid certificate (see the notes for 0.1.0).
- Diagnostics turns a capture into a short list of prioritised findings with evidence:
performance, duplicates and N+1, errors and authentication, character encodings, clocks,
and how sensitive each operation is to slow networks. - German user interface, including the menus (Settings → General → Language).
- Character encodings: every view shows bodies in their real charset, with an override.
- Map Remote / Map Local, drag & drop of archives, a timing waterfall, a host/path tree,
a theme choice, and a user manual. - macOS: one universal
.dmg; Windows: installer (.exe/.msi) or the portable
Quena_0.1.2_x64-portable.zip; Linux:.deb,.rpmand AppImage for x86_64 and arm64.
Added
- Character encodings: every text view decodes bodies in their real charset (BOM, then the
Content-Typecharset, then<?xml encoding>/ HTML<meta>, then the type's default) and
shows it ("windows-1252 · header") with a menu to view the body in another charset. UTF-16
bodies are formatted too; multipart parts and form data use their own charset; RFC 8187
filename*=parameters are shown decoded. - Diagnostics finds encoding problems: a declared charset that does not match the bytes
(“Grüße” → “Gr��e” or “Grüße”), header, BOM and document declaration that disagree, text
without any charset, double-encoded UTF-8, characters already lost (�), JSON not in UTF-8,
unknown charset names, NUL bytes in text, and compressed data without (or with a broken)
Content-Encoding. - Diagnostics finds clock problems from the
Dateheader: a server whose clock differs from
this computer (critical from 5 minutes, Kerberos' tolerance), this computer's own clock
being off (several unrelated sites agree), and servers behind one name with different
clocks. - Diagnostics (View → Diagnostics, bundled plugin webdiag): turns a capture into a short
list of prioritised findings with evidence instead of thousands of sessions — slow requests
and server time, large and uncompressed transfers, exact and semantic duplicates (OData
aware), N+1 and polling patterns, retries and double submits, HTTP errors and connection
failures, authentication loops and repeated NTLM/Kerberos handshakes, redirect chains, cookie
and caching problems, connection reuse, old TLS, CORS preflights, unbounded OData queries,
and how sensitive each operation is to latency and bandwidth (estimates per network
profile, clearly marked). Profiles: full, performance, troubleshooting, authentication,
network resilience, modernization. Scope: visible or selected sessions, narrowed to
processes or target hosts; mixed traffic of several applications is pointed out. Findings
select their sessions with one click. Reports save as JSON or Markdown, copy as a prompt for
an AI assistant (redacted), and compare with a saved report. Everything runs locally; tokens
and cookie values never reach the plugin. - Plugin API: analyzer plugins analyse a whole capture (contract in
plugins/webdiag/REPORT.md). - Inspectors remember the chosen view per kind of content, separately for request and
response (e.g. SOAP → XML, JSON → Body, Fast Infoset → its plugin view). Until a view was
chosen, the one that fits the content opens (SOAP, gRPC, WebSocket, images, form data …).
On by default; Settings → General → Inspector views turns it off or forgets the choices. - JWT plugin: decodes JSON Web Tokens in
Authorization/Proxy-Authorization(Bearer, DPoP),
cookies,Set-Cookieand common token headers: header (alg, typ, kid …), claims with the
registered ones explained,exp/nbf/iatas dates with "expired 3 h ago" / "valid for
12 min", and the signature algorithm (not verified). Encrypted tokens (JWE) show their header.
Shown in the Auth view next to Kerberos/NTLM (no extra tab); the Auth view now also lists
tokens a plugin recognises in cookies and token headers. - GraphQL plugin: requests (
application/graphqlor JSON withquery/variables/
operationName, batches, persisted queries) with the operation and the query pretty-printed,
and GraphQL JSON responses with the errors first. - Drop
.sazor.hararchives onto the window to load them. - Timeline shows a waterfall: request, DNS, connect, TLS, send, wait (time to first byte)
and receive per session, with the time of each phase in the tooltip. - Structure tab: the visible sessions as a tree of hosts and paths with counts and errors;
clicking a host or folder selects its sessions. - German user interface, including the native menus: Settings → General → Language (like
the system, English, Deutsch). Numbers and sizes follow the language (1.234, 1,5 KB). - Theme choice in Settings → General: like the system, light or dark.
- Slow and large responses stand out in the session list: duration over 1 s / 5 s and body
size over 1 MB / 10 MB are shown in amber / red. - Copy as fetch (JavaScript), PowerShell (
Invoke-WebRequest) and Pythonrequests, next
to cURL. - Map Remote: Mock Rules → Add mapping… → Map Remote forwards everything under a URL
prefix to another server (prefix:https://prod…/api/→https://staging…/api/), keeping
the rest of the path and the query; the session comment names the original URL. - Map Local: Add mapping… → Map Local serves a folder under a URL prefix (
dir:/folder
action):index.htmlfor folders, Content-Type by extension, a clear 404 for missing files;
paths that would leave the folder (.., encoded%2e%2e, symlinks outside) are refused. - Mock Rules match
prefix:for URLs that start with a given text. - User manual at https://hkiam.github.io/quena/ (MkDocs Material, sources in
manual/):
installation, capturing, HTTPS and devices, the session list, inspectors, Mock Rules,
analysis, archives, scripting, authentication, plugins, settings, shortcuts and
troubleshooting; built by the Manual workflow and published to GitHub Pages.
Changed
- The right pane's tabs show icons only when their names do not fit the pane.
- The command palette also finds commands by their English names.
- Inspector view tabs show as many views as fit the width; More only holds the ones that do
not fit, and the views are ordered by how well they fit the content.
Fixed
- Diagnostics and header inspectors (JWT, Kerberos/NTLM) opened right after start said no
plugin was installed while the plugins were still being compiled; they now show that
plugins are loading and update when they are ready. - Umlauts and other non-ASCII characters were shown as
�in inspector bodies (and in JSON,
XML, SOAP, multipart, form data, the large-text view) when a body was not UTF-8; search
did not find them either. - Composer and breakpoint edits keep the body's charset (unedited bodies are sent byte for
byte); Copy as sends exactly the recorded bytes for bodies that are not UTF-8. - HAR import: a leftover
Content-Encodingon a request whose text is already decoded is
dropped, so it is no longer reported as undecodable. - Plugins dialog: long "Applies to" lists squeezed the other columns to single characters;
the columns keep their width, the Diagnostics plugin shows what it applies to, and status
and column titles are translated. - Inspector view tabs overflowed (and hid the pane titles) after coming back to Inspect
from another right-pane tab; they are measured again when the view shows. - Diagnostics:
- A single sign-on round trip is no longer reported as a redirect loop.
- Polling during an outage is no longer a "retry storm".
- Data timestamps are no longer dropped as cache busters.
- Requests still open at capture end are neither failures nor sequential chains.
- A session-wide correlation id no longer merges separate actions.
- Transfer-time estimates agree between rules and include packet loss.
- Slow critical endpoints are never cut from the list.
- Large captures stay fast (500 000 sessions in about 2 s); the authentication check is
linear. - A cancelled or older run can no longer replace a newer report, and "Remove all" clears
the report.
- Diagnostics tab:
- It keeps the chosen finding and a running analysis across tab switches.
- It notices enabled or disabled plugins.
- Filters are reset for a new report.
- Markdown exports escape text from the traffic.
- Structure: the "(this path)" row selects exactly that path; all open levels refresh in
one pass and less often. - Map Local serves large files without blocking the proxy and answers
500instead of a
truncated file when reading fails. - Dropped archives: temporary copies are removed even when an import fails or is
cancelled, left-overs at startup; drops are limited to 8 GiB and need free disk space. - GraphQL formatting stops at a size limit instead of growing without bound; JWT dates given
in milliseconds are recognised. - Language switch: nothing changes when the choice cannot be saved; Exit is translated.
Security
- Copy as PowerShell / cURL: a crafted HTTP method or typographic quotes in a header or
body could make the pasted command run other programs. Methods are quoted
(-CustomMethodfor non-standard ones), all PowerShell quote characters escaped, control
characters written explicitly; duplicate header names are merged. - Map Local verifies the opened file itself (no symlink swap between check and open), and
prefix:rules that name only an origin no longer match look-alike hosts or other ports
(https://prod.example.com≠ `https:...
Quena v0.1.1
Faster start and capture switching, more platforms, and more robustness. Packages are still
not signed with a paid certificate (see the notes for 0.1.0).
- macOS: one universal
.dmgfor Apple Silicon and Intel. - Windows: installer (
.exe/.msi) or the portableQuena_0.1.1_x64-portable.zip. - Linux:
.deb,.rpmand AppImage for x86_64 and arm64.
Added
- macOS builds are universal (Apple Silicon and Intel); Linux packages for arm64 (aarch64)
in addition to x86_64. - UI end-to-end tests that start the real app and drive it through WebDriver (Linux, in CI).
- Requests the HTTP parser rejects (malformed request line or headers, too large heads) appear
as aborted sessions with the raw bytes received, instead of only a 400 to the client.
Changed
- Layout uses the whole window at every size: the Path column of the session list takes the
width left over by the other columns; in a narrow right pane request and response go above
each other automatically and the pane's tabs show icons only; toolbars in the inspectors wrap
instead of cutting off buttons; splitters keep a usable minimum size for every area. - The capture switch reacts immediately and shows "Starting…"/"Stopping…" while the system
proxy is being changed. - Stopping the capture also closes open client connections, tunnels and WebSockets (after the
request in flight), so nothing more is recorded. - WebSocket over HTTP/2 (RFC 8441) is no longer offered to browsers; they open WebSockets on a
separate HTTP/1.1 connection, which Quena records frame by frame. - Faster start: the window no longer waits for the capture to start (setting the system proxy,
loading a PAC file), for plugins to compile or for the OS root certificates to load. Plugins
are compiled once and cached (plugin-cachein the data folder); the UI's startup bundle is
60 % smaller (editors, diff view and the QR code load on first use). - Starting and stopping the capture on macOS changes all network services at once instead of
one after another (several times faster on Macs with many network services). - Portable mode (a
portablefile orquena-datafolder beside the executable, on every
platform) now keeps the web view's cache and storage inquena-dataas well, and bundled
plugins are found in apluginsfolder next to the executable.
Fixed
- Body views of small responses left a white area below the text (the editor did not fill
the pane when no notice was shown above it). - Mock Rules: the Latency and Hits column headings broke in the middle of the word.
- Windows: logging off or shutting down while Quena runs restores the system proxy (it could
stay pointed at Quena until the next start, leaving the user without internet). - Starting the capture at launch and toggling it at the same moment could start it twice.
Quena v0.1.0
First public release of Quena, a local HTTP(S) debugging proxy for macOS, Windows and Linux:
capture, inspect, change and replay HTTP/1.1, HTTP/2, HTTPS, WebSocket and SSE traffic, with
mock rules, breakpoints, a composer, JavaScript rules, WebAssembly plugins, automatic
authentication (NTLM, Kerberos, Basic) and SAZ/HAR import and export.
Installing: packages are not signed with a paid certificate or notarized yet.
- macOS (
.dmg, Apple Silicon): on first start macOS warns about an unidentified developer —
open System Settings → Privacy & Security and choose Open Anyway. - Windows (
.exe/.msi): SmartScreen may warn — More info → Run anyway. - Windows portable (
Quena_0.1.0_x64-portable.zip, xcopy deployment): unzip anywhere and
startQuena.exe— no installation; settings, sessions and the root certificate stay in
quena-databeside it (seeREADME-portable.txt). - Linux:
.deb(Debian, Ubuntu),.rpm(Fedora, openSUSE) or the AppImage (x86_64).
This is an early 0.x release: settings, file formats and the plugin API may still change.
Added
- Linux support on par with macOS and Windows: system proxy for GNOME and KDE Plasma (restored
on quit and after a crash), root certificate trust for Chrome/Firefox (NSS) and the system
store (viapkexec), process attribution via/proc, credentials in the Secret Service
keyring, Kerberos single sign-on via GSSAPI (loaded at runtime),xdg-open/file manager
integration. Packages:.deb,.rpm, AppImage; built and tested in CI on Ubuntu 22.04. - Double-clicked or "Open With"
.har/.sazfiles are loaded (all platforms). tools/linux/Dockerfile: the Linux build and test environment.- Hardening against broken and hostile traffic: timeouts for stalled clients and servers
(request head, TLS handshake, DNS, upstream CONNECT, response head, idle tunnels and
WebSockets), limits for concurrent connections, buffered bodies, decompression, imports and
inspectors, refusal of request loops into Quena itself, bounded PAC evaluation and download.
Damaged settings, rules, root certificate, database rows and system-proxy backups no longer
block the start or lose data; a failing view shows an error instead of a blank window. - New app icon.
- Header inspector plugins: the plugin API gains an additive
header-pluginworld (existing
decoder plugins keep working). The bundled auth-tokens plugin decodes SPNEGO, Kerberos
(AP-REQ/AP-REP/KRB-ERROR) and NTLM Type 1/2/3 tokens in the Auth inspector and flags
Negotiate that fell back to NTLM. (Marian Gavalier) Ctrl/⌘+/-/0zoom the whole UI;cargo build --profile localfor fast optimized
local builds. (Marian Gavalier)
Changed
- Own default layout: session list left, request and response side by side, rows coloured by
outcome (5xx red, 4xx amber, redirects muted). The dense stacked arrangement is available as
the Classic layout (first start, Settings → General). - Own look: SVG icons (Lucide), a capture switch, method and status badges in the session list,
a state bar for in-flight/paused/mocked sessions, tunnels shown by target host with a badge. - Command field in the toolbar (
Alt+Q) replaces the bar below the list; new command palette
(Ctrl/⌘ K) with every menu command. - Inspectors: request and response cards with segmented tabs (Headers, Body, Cookies, Raw and
content-specific views), the rest under More; headers as a filterable table in wire order
with topic tags and optional A–Z sorting. - Menus: File, Edit, Capture, View, Tools, Help; breakpoints, mock rules, rules script and
authentication are under Capture, the Hide … items under View → Hide in List. - Own names: Mock Rules, Text Tools, Inspect; inspector tabs Plain Text, Body,
Form Data, Hex, Image, Preview, Encoding; Rules Script…; Replay …. Filter/command syntax
and shortcuts are unchanged. Help → Coming from Fiddler Classic… maps the names. .sazis registered as a viewer (macOS rank "Alternate") and not at all on Windows, so Quena
never takes over another application's file association.
Fixed
- Automatic authentication falls back to the next offered scheme when the server rejects one
(e.g. Negotiate advertised but only NTLM working). - NTLM no longer uploads the request body twice (the Type 1 leg now goes without it).
- Plugin call timeout follows wall-clock time on loaded machines.
- Sorting 500k sessions by host no longer allocates per comparison (several times faster on
Windows). - Request bodies could go missing when a response finished before its request body was
recorded (both are now recorded in order, and a session is saved only when all its bodies are). - Sessions whose client disconnected stayed "in flight" forever; they now end as aborted.
- Windows:
Ctrl+Fopened the web view's page search instead of Find Sessions; browser
shortcuts (Ctrl+R,F5,Ctrl+P) no longer reach the web view. - macOS: downloaded builds were reported as "damaged" (incomplete signature); the bundle is now
signed ad hoc, with the JIT permission the plugin engine needs. - Tab strips in Settings, Composer and Connect Device had no spacing between titles.
- Raw inspector uses the whole pane; larger base text size (13 px). Documented toolchain
minimums corrected (Rust 1.95, Node.js 20.19+/22.12+). (Marian Gavalier)