Skip to content

Releases: wirebench/wirebench

v4.0.0

Choose a tag to compare

@github-actions github-actions released this 09 Oct 14:17
736f00b

Added

  • WS-Security debugger. The response's WSS inspector now says why a signature, decryption or
    timestamp failed. It shows the part that changed, with its expected and computed digest and the
    transforms used, or a SignatureValue that fails while every part matches. It names the signer token
    or decryption certificate the message asked for and did not find, and the clock skew against the
    timestamp. It also lists the Security header step by step. Preview secured request shows a
    request's secured envelope and its steps before Send (#57).
  • WS-Security from the WSDL's policy. When a WSDL attaches a WS-SecurityPolicy to an operation, the
    request's Auth inspector shows the tokens, the signed and encrypted parts, the algorithm suite and
    whether TLS is required. Apply policy turns it into an outgoing WS-Security configuration in one
    click, and a badge says whether the request satisfies the policy or lists what is still missing (#58).
  • Managed preferences. On a managed machine, a policy.yaml in a system location
    (%ProgramData%\Wirebench, /Library/Application Support/Wirebench or /etc/wirebench) locks the
    proxy, the minimum TLS version, the CA bundle and update checks. Locked settings are read-only in
    Preferences and marked Locked by policy; the user's own values come back if the policy is
    removed (#67).
  • Certificate expiry warnings. Problems warns before a certificate in the workspace expires:
    keystores and the CA bundle are checked on their own, and Check Certificate Expiry also reads
    the chain every TLS endpoint of the open projects presents, from a verified handshake alone; an
    endpoint whose chain doesn't verify is an error. The window is
    Preferences → SSL → Expiry warning (30 days); the SSL inspector uses it too (#70).
  • Secrets from external managers. Map a ${secret:name} to a Vault, AWS, Google Cloud or Azure
    secret, a 1Password item or the keychain, from Secret Sources… in the command palette. Wirebench
    fetches the value at send time with the manager's own CLI and your login, keeps it in memory only
    (Preferences → Secrets, Clear Secret Source Cache) and masks it like any other secret, so
    Toggle Show Secrets in HTTP Log reveals it too. A shared mapping
    is used only after you approve it on this machine, and again after any change; the Problems list
    also flags a request that isn't approved. wirebench run, send, call and mcp fetch the same mappings with
    --trust-secret-sources or --trust-secret-sources-hash, and wirebench secrets list shows each
    secret's source and the mapping's hash (#37).
  • Kerberos authentication. A request, an API, a SOAP interface or endpoint, and a definition
    fetch can authenticate with your Windows sign-in or kinit ticket over HTTP Negotiate, with an
    optional SPN and, on Windows, another account. Kerberos only: nothing falls back to NTLM. The
    WebSocket upgrade and gRPC calls send it preemptively; the CLI and MCP send it too (#40).
  • WS-Trust. Request SAML tokens from a security token service with a username or a client
    certificate, cached for their lifetime; each token request shows in the HTTP Log. wirebench run --verbose reports each token request by host and status, never the token. A token service can
    also be asked with a Kerberos ticket (#41).
  • SAML tokens in outgoing WS-Security. Built from a form (SAML 1.1 or 2.0, optionally signed as
    issuer) or supplied as XML. Token signatures in the HTTP Log are masked (#41).
  • Signatures can refer to a SAML token (holder-of-key) and cover it through the STR-Transform (#41).
  • License binding. A license can be bound to one server. The server mints an id when its database
    is first migrated, and a license that carries a different serverId is refused as wrong-server
    with a message naming both ids. Licenses without the field keep working on any server. The id shows
    as the first line of wirebench-server admin license show and as Server id, with a Copy button,
    on the License tab (#203).
  • Postman environments and globals. Import… reads Postman environment and globals exports
    (Import Postman Environment…, Import Postman Globals…). An environment becomes a workspace
    environment, renamed when the name is taken and never made active; globals merge into Globals.
    Secret-typed values go to the secret store, and nothing that already exists is overwritten. A
    Postman collection's own variables now arrive as project properties instead of being dropped (#64).
  • HAR import. Import… reads HAR 1.1 and 1.2 captures (Import HAR…): one REST API per
    origin, one request per method, path and set of query names. CORS preflights, non-HTTP URLs and,
    unless Include static assets is ticked, static assets are skipped. Recorded responses can be
    left out, written to History at the time they were recorded, or saved as examples. Recorded
    credentials and cookies are never imported: credential-named values are emptied from request
    bodies and masked in examples, in JSON, form and XML alike (#64).
  • .http files. Import… reads .http and .rest request files (Import .http File…)
    into a REST API, with a WebSocket API for WEBSOCKET requests. @variables become project
    properties, response handlers are kept as text under imported-scripts/ and never run, and
    GRAPHQL and GRPC requests are skipped with a warning. When a picked file has
    http-client.env.json or http-client.private.env.json beside it, the dialog offers to import
    those environments too; Import HTTP Client Environments… imports them on their own. Private
    values and credential-named literals become secrets, and an imported environment is never made
    active. Credential-named literals in JSON, form and XML bodies are emptied (#64).
  • OpenCollection. Import… reads OpenCollection 1.x YAML (Import OpenCollection…), as one
    document or as a folder picked by its opencollection.yml. HTTP and GraphQL items become a REST
    API, gRPC items a gRPC API and WebSocket items a WebSocket API, with their folders. Variables
    become project properties and environments workspace environments, never made active; secret and
    credential-named values become secrets. Scripts are kept as text under imported-scripts/ and
    never run, status, response-time and JSON body assertions become request assertions, and a folder
    collection's gRPC API gets the .proto files it names. A folder is read without following links,
    up to 5,000 files and 50 MB. Literal credentials are emptied from bodies, XML included, and from
    the OAuth 2 URLs; a folder's root dropped on its own is refused with a message saying to pick it
    from its folder (#64).
  • Response examples. A REST request can keep recorded responses as examples, up to 5 from a HAR
    import, one per status. The response pane's Examples menu shows one read-only under a banner,
    and Delete example removes it (#64).

Changed

  • Project format 7. Response examples are saved with the project, so the project format is now 7:
    an older Wirebench cannot open a project saved by this one.

Fixed

  • Import cURL warns about a --negotiate account with no password. The preview now notes that the
    Kerberos account needs a password on Windows and is refused on macOS and Linux until you use Clear
    account
    (#272).
  • Update Definition from another host no longer reuses the interface's Kerberos SPN or Basic credentials: a URL on a different origin is fetched with the SPN defaulted to that host, and without the interface's username and password (#271).
  • A REST contract tool no longer asks for a query API key. When the API's auth is a query API
    key, the tool's query argument leaves that parameter out, so the request carries the key once
    instead of key=<argument>&key=<secret> (#225).
  • wirebench mcp on stdio keeps worker output off the protocol stream. A line written to stdout
    by one of the engine's worker threads now goes to stderr with the rest of the server's output, so it
    can no longer corrupt the frames (#182).
  • A partly masked XML value no longer leaves the message unparseable. Where a secret is only part
    of an element's text (<Auth>Bearer <redacted></Auth>), send, call, query, validate and
    history_diff now write the marker as escaped text, so the body and its History entry still parse (#183).
  • Issued-token status while typing. The cached-token line under an issued-token entry reads
    again once you stop editing, not on every keystroke (#279).
  • A WebSocket upgrade refused with 401 drops the OAuth2 token. The next connect fetches a new
    one instead of reusing the stale token until it expires, as a REST 401 already did. A server that
    cannot be reached, a 403, a timeout and a cancel keep the token (#193).
  • gRPC deadline in a run. A unary gRPC call that passes its deadline in a run now errors with
    timeout, as a REST request or a stream does, instead of reporting DEADLINE_EXCEEDED as a result
    that an unasserted call passed with. A status 4 the server returns before the deadline is still a
    result, and sending a call from the app still shows status 4 (#194).
  • Kerberos ticket wait. A slow or unreachable Kerberos server no longer holds a send or a
    Cancel: the wait counts against the request's timeout (the handshake timeout for a WebSocket, the
    deadline for gRPC), Cancel stops it at once, and it fails with timeout and a message naming the
    SPN (#267). A WS-Trust token request with a Kerberos credential does the same: the ticket wait and
    the call to the token service share the request's timeout, and Cancel stops either (#278).
  • OpenCollection proto imports. A folder collection's gRPC API now arrives with its definition
    when its .proto files import other files from the collection's folder: each...
Read more

v3.1.0

Choose a tag to compare

@github-actions github-actions released this 04 Oct 14:53
f89535b

The first release since 2.2.1, carrying both the 3.0 and 3.1 milestones; there is no 3.0.0. The major
version is @wirebench/engine's public exports: the names that
dated from the SOAP-only engine are renamed, and what the new protocol registry replaces is removed,
with no deprecated aliases. Existing projects and workspaces open unchanged, and the wirebench
command line keeps its flags and report shape; the behaviour changes this release does make are listed
under Changed and Fixed. The project format version does move, to formatVersion: 6, because of request
scripts (see Added): a project this build saves opens only in a build that has them. The protocol
modules themselves do not change the project folder format.

Breaking

  • @wirebench/engine: SOAP-era names renamed. importDefinition is importWsdl; ImportSource,
    ImportOptions, ImportCacheOptions, ImportProgress, ImportProblem and ImportResult gain a
    Wsdl prefix (WsdlImportSource, …); summarizeOperations and OperationSummary are
    summarizeSoapOperations and SoapOperationSummary; generateRequest and generateEmptyRequest
    are generateSoapRequest and generateEmptySoapRequest; toSendInput, ToSendInputArgs and
    SendRequestInput are toSoapSendInput, ToSoapSendInputArgs and SoapSendRequestInput;
    SendAttachmentOptions is SoapAttachmentOptions. Signatures are unchanged.
  • @wirebench/engine: exports removed. prepareSend and PreparedSend (send through
    createRunSender); assertSupportedKind and apiKindOf (ask ProtocolRegistry.status);
    RequestDef (it was an alias of SoapRequestDef); scriptTypesFor; ScriptProtocol (it is
    string); and RequestScriptTypes.soap, which is now the opaque binding.
  • @wirebench/engine: protocol is a string. RequestResult.protocol,
    AssertionSubject.protocol and ScriptedRequest.protocol were the union 'soap' | 'rest' | 'grpc'.
    The JSON report's protocol field is typed the same way; the values a run writes are unchanged.
  • @wirebench/engine: one send path. ProtocolRun.send is replaced by open, which starts a send
    and hands back an exchange (its events, push, halfClose, close, cancel and result), and
    resolve, which gives what a send would send with nothing connected. RunContext.host, a SendHost,
    replaces getSecret, proxyFor, onSecretValue, fetchToken and tokenSource, and also carries
    what a host can lend a send: TLS anchors and identities, preferences, cookies, a contract check and
    gRPC schemas. prepareRest, prepareSoap and prepareGrpc, the modules' own prepare functions (never exports of
    the main entry), are removed. openExchange,
    resolveExchange and SendHost are added, with the types around them (ExchangeHandle,
    ExchangeOptions, SendFailure). The desktop, the command line and MCP all send through them.

packages/engine/README.md has the full tables and a
before and after for the two changes that need more than a rename. The package's subpaths (./xml,
./rest, ./json, ./grpc, ./asyncapi, ./snapshot, ./detect) are unchanged.

Added

  • send baseline check. send (the MCP tool, and wirebench send --baseline) compares the
    response with the request's golden and returns the differences (#218).
  • wirebench run --update-baseline saves each changed response as its request's golden, keeping
    its ignore rules, and lists the files it wrote (#217).
  • Cookie jar. Cookies responses set go into a jar per workspace, kept across restarts (encrypted
    with the system keychain) except session cookies. A REST request with Send cookies on sends the
    matching ones, per redirect hop. View → Show Cookies opens a manager to view, add, edit and
    delete them, and the response's Cookies tab says what was stored or ignored. wirebench run
    keeps a jar for the run (#44).
  • Current values. Every variables table has a Current column: a session-only value that
    replaces the committed one for sends and previews. The store is memory only; a request that is
    sent records what it sent, as for a committed value, so keep credentials in ${secret:…} (#44).
  • HTML preview. The Preview tab renders an HTML response or webhook capture as a static page in a
    sandboxed frame: no scripts, forms, navigation or network (#48).
  • wirebench run --baseline compares each response with its committed golden and fails on a
    semantic difference; --require-baseline makes a missing golden an error (#36).
  • Contract operations as MCP tools (#33). wirebench mcp lists every imported SOAP operation and
    OpenAPI endpoint as a tool of its own, with a JSON Schema built from the XSD or the OpenAPI schemas.
    An agent calls it with JSON; Wirebench builds the envelope or request, sends it under the interface's
    or API's endpoint, auth and secrets, records it in History, and returns the response as JSON. The
    list follows the project as it changes, at most 128 tools are served, and --tools picks the
    interfaces and APIs. wirebench call runs the same from a terminal, and operations rows show each
    operation's tool name.
  • An Assertions tab on every editor. The REST, SOAP, gRPC and WebSocket editors have an Assertions tab.
    Every editor Send checks the request's assertions and shows the result in the response pane's
    Assertions tab; callback assertions are still checked in runs and sequences only (#192).
  • A WebSocket request carries assertions: (part of formatVersion: 6). Runs, send and MCP send
    check them, and --require-assertions sends a WebSocket request that has them (#192).
  • A landing site. https://wirebench.github.io/wirebench/ now has a home page, a features page and a
    download page built from the latest release; the user guide moved to
    https://wirebench.github.io/wirebench/docs/.
  • Protocol modules in the engine. SOAP, REST, gRPC and WebSocket each sit behind one interface,
    held in a registry, so the loader, the writer, the run loop and the script host no longer branch on
    the protocol (ADR-0017, #184). Two
    things follow for a project. An interface or API of a kind this build does not know no longer stops
    the project from opening: it is reported as a container-unsupported problem, the rest of the
    project loads, and a save leaves that container's files exactly as they were. And wirebench send
    names such a container, with the reason, where it answered that no request matched. The registry
    also carries feature switches for each protocol and for scripts; every one is on, and nothing in the
    app or the command line turns one off yet. @wirebench/engine exports the module interface for
    Wirebench's own use, tagged @internal: it is not a plugin API.
  • Agents over MCP, and the same verbs in the terminal. wirebench mcp serves one project to a
    coding agent as MCP tools — import, operations, generate, send, validate, query,
    history_list, history_diff — over stdio, or over Streamable HTTP on 127.0.0.1 behind a bearer
    token. send needs --allow-send (and --env limits where it goes), import needs
    --allow-write, and every result is redacted, secrets included. The same capabilities are CLI verbs
    (wirebench import, operations, generate, send, validate, query, history list|diff),
    with --json for the exact result. A send from the terminal or an agent lands in the desktop's
    History, and an open History panel refreshes when another process writes the file (#32).
  • send takes WebSocket requests. wirebench send and the MCP send tool send a saved WebSocket
    request as wirebench run does: open the socket, send the saved messages, wait for a reply, close,
    and return the frames collected, masked. A session with no reply before the timeout fails with
    timeout, returning no frames and writing no History; a server that refuses or cannot be reached
    fails with ws-handshake-refused. The send lands in the desktop's History as the app's own
    WebSocket sessions do, tagged cli or mcp. operations lists saved WebSocket requests by path. A name a REST and a WebSocket request
    share is now ambiguous where it used to resolve to the REST request; gRPC requests are still refused.
    A saved WebSocket request without assertions errors under --require-assertions in a run (#184).
  • Streaming requests run. wirebench run with no selector, wirebench run --sequence, and a
    sequence in the app now send WebSocket, streaming gRPC and Server-Sent Events requests, which a run
    used to skip or refuse. A gRPC client or bidirectional stream sends its saved messages in order and
    half-closes; a WebSocket request sends its saved messages and closes after the last reply; an event
    stream is read until it ends. The run's timeout bounds every one of them, and a stream it cuts fails
    with timeout instead of passing. Everything received is what the request's assertions and a
    sequence's transfers read. A new error code, exchange-not-streaming, answers a message pushed to,
    or a half-close asked of, a send that takes none (#184).
  • Request scripts. A SOAP, REST or gRPC request can have a pre-request script, which runs just
    before the send and can change it (sign the body, add a header, fill in a field), and a
    post-response script, which checks the response with tests and keeps values for later requests.
    Scripts are TypeScript typed from the request's own contract — the operation's XSD elements, its
    OpenAPI schemas or its .proto messages — so the Scripts tab completes the message and a wrong
    path is an error before anything is sent. The response's Script tab shows the tests and the log.
    A value a script keeps is read by later requests as ${#Sequence#name}: in a sequence run, in
    `...
Read more

v2.2.1

Choose a tag to compare

@github-actions github-actions released this 21 Sep 10:11
fac8d8c

Fixed

  • The update check no longer offers an older release. A build newer than the latest published
    release — 2.2.0 while 1.1.0 was still the newest public one — was offered that older release as an
    "update", and Download would have installed it over the running version. An update is now
    offered only when the release is newer than the one running.

v2.2.0

Choose a tag to compare

@github-actions github-actions released this 21 Sep 10:56
8b75687

Added

  • WebSocket request kind. A fourth container beside SOAP, REST and gRPC, in the same project, workspace,
    environments, history and search. New WebSocket API… takes a ws:// or wss:// URL; a request under it
    connects with headers, query parameters, subprotocols, the shared auth kinds that are a header or query
    value, the resolved proxy, a client certificate and the custom CA bundle. Every frame — sent or received,
    text or binary, control or data — appears on a live timeline as it arrives, with a pretty-printed view for
    JSON or XML text one toggle from the raw bytes. While connected, the composer sends a typed or saved
    message (${…} properties expand at send time); Disconnect closes with a chosen code (1000 or
    3000–4999) and reason, and the close frame and every ping/pong show as control rows. The handshake is one
    HTTP Log entry (GET, its headers, the 101 or the refusal, timing and TLS); the session appears in
    History when it closes, capped to its first 400 and last 100 frames within 1 MB — History's own re-send
    stays offered for a SOAP entry only. kind: websocket writes under the existing formatVersion: 3; a
    project without a WebSocket API is byte-identical to before. See
    docs/specs/2026-09-19-websocket-request-kind-design.md
    and the update to ADR-0007.

  • Fleet-ready releases. An MSI installer for Windows x64 and arm64, for Intune and other fleet
    tools (msiexec /qn); a CycloneDX SBOM with every release; build and SBOM attestations on tagged
    releases, checked with gh attestation verify. Windows signing through SignPath Foundation is wired
    into the release workflow and switches on with its secrets. Silent installs and download
    verification are on the install page, and the site has a code-signing policy.

  • User guide. A documentation site at https://wirebench.github.io/wirebench/: install and first run on
    macOS, Windows and Linux, a ten-minute walkthrough, a guide for every feature area, a command and
    shortcut reference generated from the app, troubleshooting and an FAQ. It is published from main on
    every push, and its screenshots are shot from the app by the e2e suite.

  • Switching guide. A Switching section on the site, one page per source — Postman collections,
    legacy SOAP projects, OpenAPI and Swagger, and cURL commands — each saying what carries over, what
    does not, and where the equivalent lives in Wirebench.

  • cURL import reads --json, -G and -I. --json becomes a JSON body with its two headers,
    -G moves the data into query rows, and -I asks for HEAD.

  • CLI runner: wirebench run and wirebench secrets list. A new package, @wirebench/cli
    (binary wirebench), runs the requests already saved in a project from a pipeline: status,
    soap-fault, match (XPath/XQuery/JSONPath), schema and sla assertions declared per request;
    cli, junit, json and html reports; secrets resolved from WIREBENCH_SECRET_<NAME> /
    WIREBENCH_SECRET_<REF> environment variables, never from the desktop's keychain-backed store;
    and exit codes a pipeline can branch on (0 pass, 1 assertion failed, 2 usage/load, 3 run error,
    130 interrupted). gRPC unary and OAuth2 client-credentials are not in this release. See
    docs/cli.md and
    docs/specs/2026-09-18-cli-runner-design.md.

    Project format moves to version 4. Saving a request now carries an optional assertions:
    list and an optional …Env name beside a passwordRef/tokenRef/valueRef/clientSecretRef.
    Both are additive, and a version-3 project migrates in memory without any data moving — but
    because this format drops unknown keys on save, saving a project with this version writes
    formatVersion: 4, and an older Wirebench refuses to open it
    (format-too-new). Everyone
    working on a project a 2.2+ build has saved needs to be on 2.2 or later too.

  • CI recipes for the runner. @wirebench/cli and @wirebench/engine are published to npm; a
    container image is published to ghcr.io/wirebench/wirebench-cli (linux/amd64 +
    linux/arm64); a GitHub Action (wirebench/wirebench/action@<tag>) and a GitLab template
    (templates/gitlab/wirebench.gitlab-ci.yml) wrap them. All four ways to run in CI map secrets
    to WIREBENCH_SECRET_<NAME> the caller sets — none of them holds or asks for one itself. See
    "Run in CI" and
    docs/specs/2026-09-19-ci-recipes-design.md.
    Publishing itself waits on the first tagged release after the npm organisation and the GHCR
    package's visibility are set up (see "Before the first publishing
    release"
    ).

  • HTTP Log: rows kept and Preserve log. The number of rows kept is a setting (Preferences › Behaviour,
    100–5000, default 500). Preserve log keeps the rows in memory across closing or switching a workspace;
    it is never written to disk and is off again at every launch.

  • HTTP Log: compare two rows. Cmd/Ctrl+click a second row to compare the two — a summary of each,
    request and response headers marked added/removed/changed, and request and response bodies side by
    side (pretty-printed when both are JSON or both XML). Escape goes back to one row.

  • HTTP Log: waterfall. A Waterfall column shows each row's start and duration across the rows shown,
    split into connect, TLS, wait and download (hover for the breakdown; hidden while a row is selected); the
    Timing tab notes a reused connection.

  • HTTP Log: search, a Name column and sort. Search matches headers, bodies (first 256 KiB) and the
    request name, with regex and match-case toggles; a Name column shows the saved request; click Time,
    Name, Status, ms or Size to sort.

  • HTTP Log: Export HAR. Saves the rows the filter shows, in display order, as a HAR 1.2 file;
    headers, URL parameters, WS-Security passwords and JSON/form secrets are always masked, whatever
    the show-secrets toggle says. Failed sends carry an _error, truncated bodies _truncated.

  • HTTP Log row menu. Right-click a row, press its detail's ⋯ button or press Shift+F10 on the selected
    row to copy it as cURL (POSIX or PowerShell) from what was sent, copy its URL, request or response headers
    or response body, resend the saved request as it is now, or open the request.

  • HTTP Log: failures before the request is built. A send that fails before the request is built (invalid URL,
    proxy lookup, OAuth2 token fetch) now appears as a "Failed · before send" row, and its detail says the request
    never went on the wire.

  • Importing a legacy single-XML SOAP project. Import Legacy SOAP Project… (or Legacy SOAP project in
    Import…, which also detects the file) brings a whole project file from an older SOAP workbench into a
    Wirebench project. It carries across the SOAP interfaces with their endpoints, every saved request (envelope
    unchanged, and gzip-compressed envelopes decoded), usernames, timeouts, encodings, project properties, and
    environments with their endpoint overrides. Each interface resolves from the definition the file carried, so
    the import works offline and the project reopens offline. What does not come across is listed in a report you
    can copy: passwords (to be re-entered), test suites, mock services, REST services, WS-Security and auth
    profiles. Scripts are kept, never run, under imported-scripts/. Picking such a file as a plain WSDL now says
    which format to choose instead of failing partway through.

  • Completion in the gRPC message editor. Typing a key in the Message tab offers the fields of the message
    the cursor is in — not just the method's request type, so a nested field's own fields are offered inside it,
    and a repeated field's items are offered like the field itself. Accepting one writes the key with an empty
    value of the right JSON shape, and the suggestion carries the declared type, the field's .proto comment and,
    for an enum, its values. A key the object already holds is not offered, nor is the rest of a oneof whose
    member is already written. Other JSON editors in the app are unchanged. See
    docs/specs/2026-09-18-grpc-message-completion-design.md.

  • gRPC live streaming and interactive bidirectional send. A streaming call now shows itself while it runs:
    the response pane raises its tabs as soon as the call opens, the server's initial metadata appears when its
    headers arrive, and each reply is appended as it is decoded rather than all of them at the end. For a method
    whose client streams, Open stream starts the call and leaves the request side open — a composer under the
    response pane sends one more message at a time and Half-close stops sending without ending the call, so a
    bidirectional method can be held as a conversation. Every message pushed by hand is part of the exchange that
    is recorded, in requestMessages and in the raw request bytes. See
    docs/specs/2026-09-18-grpc-live-streaming-design.md.

  • gRPC server reflection. Point Wirebench at a running gRPC server and it describes itself: the Import
    dialog's gRPC format gains a Server tab taking an address, the reflection version (automatic by default —
    grpc.reflection.v1, falling back to v1alpha) and whether to ask a server whose certificate does not verify.
    What comes back builds the same folder-per-service, request-per-method API a .proto import builds, and is
    cached with the project as the descriptor set the server sent. The gRPC API tab's Definition card gains
    Refresh from server: asking again adds a request for a method the server has gained and badges one wh...

Read more

v2.1.1

Choose a tag to compare

@github-actions github-actions released this 21 Sep 10:56
bb1c0a4

Changed

  • Documentation. The README's screenshots are re-shot against 2.1.0: the explorer as it looks
    now (fold chevrons, the method column, the tighter nesting) and the unified Import… dialog in
    place of the retired Import WSDL… entry. The capture spec dismisses the folder watcher's
    "changed on disk" banner first, so a picture no longer documents a bar the reader will not see.

v2.1.0

Choose a tag to compare

@github-actions github-actions released this 21 Sep 10:56
370604e

Added

  • Shared workspaces. A workspace can now be shared with a team: Share this workspace… turns
    it into a git repository (remote optional, branch default main) or moves it into a synced
    folder; Join shared workspace… clones one from a URL or opens an existing clone or synced
    folder. Every save becomes a commit with a generated message; a status-bar Sync badge and panel
    pull, push, fetch and show recent commits; a conflict resolver lists each conflicted entity with
    Keep mine / Keep theirs / Open file. Environments now travel with the workspace like
    everything else. See docs/collaborate.md and
    ADR-0008.

  • Not on this machine. In a shared workspace, a request field whose secret ref has no value on
    this machine shows Not on this machine with an Enter… button; the value you type is stored
    locally under the same ref, so the shared files and your teammates' files never change.

  • Git preferences. Preferences → Git shows the git executable Wirebench will run and its
    version, with Locate… to pick a specific binary and Clear to return to automatic discovery.

Changed

  • Workspace format 3. activeEnvironmentId moves out of workspace.yaml into a
    machine-local local.yaml (it was never meant to be shared between members), and writtenBy is
    dropped from the manifest entirely. A version-2 workspace still opens and lifts its active
    environment on first open; a version-3 workspace is refused by an earlier build with the existing
    "created by a newer version of Wirebench" error. A shared workspace also gains a machine-local
    share.yaml (remote, branch and sync settings) alongside it, never written into the shared tree.

Known limitations

  • Line-level merges. Two edits to the same request's envelope (or any other single file) can
    still conflict at the line level even though one file is one entity; the conflict resolver
    covers this today, a YAML-aware merge driver is a listed follow-up.

  • No shared secret values. Secret refs travel with a shared workspace; the values behind them
    stay per member. Shared, encrypted secret values are a follow-up for Wirebench Server.

  • Not every missing secret raises the named error. A missing endpoint password or WSDL-import
    password fails at send time with a message naming the field; a missing keystore passphrase,
    proxy password, or WS-Security secret fails silently instead — check the field for Not on this
    machine
    .

  • Synced folders have no merge. A folder share has no Sync control; two members saving the
    same file race on whatever the folder's own sync tool does about it, usually last-write-wins.

v1.1.0

Choose a tag to compare

@github-actions github-actions released this 12 Sep 20:55
26795bf

Added

  • Workspaces. Wirebench now groups any number of projects into a workspace stored under
    Electron's userData, with no folder to manage — the launch picker creates or opens one by
    name. A workspace holds its own environments, shared by every project it contains, with a
    ${#Workspace#…} property scope; an interface's effective endpoint is the workspace
    environment's override, falling back to a linked project's own (name-matched) environment,
    then the interface's default. Link existing project folder… and Import project folder…
    bring an external project in for teams that keep it in git; Export project… writes it back
    out. Removing a project is trash-only and confirmed; a linked project's folder is never
    touched. Tabs, the explorer, and History span every project in the open workspace, and the
    last-open workspace (with its tab set) reopens on launch.

  • Environments view. Environments moved out of the right panel into their own left-menu view
    (activity bar → Environments, view.showEnvironments), listing Globals, the workspace and
    every environment; opening one shows a variables table and an endpoint-overrides table, Postman
    style, instead of a grid.

  • Per-variable enabled checkbox. Every property scope — project, environment, workspace,
    workspace environment, and globals — can now disable one variable without deleting it; an
    unticked variable's value stays on disk but is skipped during resolution, falling through to
    the next scope down.

  • Project tab. Selecting a project row opens it as a normal pinned tab instead of a side
    panel, showing the project's own settings and properties.

  • Code slide-over. A right icon rail replaces the old right panel; its one icon today opens a
    slide-over showing the active request as curl (view.toggleCode, Mod+Alt+B, the shortcut
    freed by the removed Details-panel toggle), closed by Escape or the rail icon again.

  • Collapsible, resizable panels. The sidebar, console and Code slide-over can each be
    collapsed and resized by dragging their handle, by the chevron in the panel's own header or its
    status-bar toggle, or by double-clicking the handle to snap collapsed or restored. Dragging the
    sidebar's or the console's handle past the panel's minimum closes it, and dragging the same
    handle back out reopens it; sizes and collapsed state persist across a relaunch.

  • Environment selector in the title bar. The active-environment switcher moved from the status
    bar to the top-right of the title bar, beside the theme toggle.

  • Preferences dialog. Settings open as a modal dialog from the activity bar's foot (or
    preferences.open) instead of a sidebar list plus an editor tab.

  • Per-tab save. Mod+S saves the request tab in front of you, and each tab shows its own
    unsaved dot; Save All (Mod+Alt+S) saves every open project. The project tab shows
    Unsaved changes / Saving… / Saved beside the project name.

  • Autosave preference. Preferences → Editor → Autosave projects turns autosave back on;
    turning it on mid-session writes any outstanding edit straight away.

  • Code panel highlighting. The curl / PowerShell preview is rendered as highlighted code,
    with flags, strings and heredoc bodies told apart.

Changed

  • Saving is manual by default. Edits stay in the open project until you save; closing a
    project or quitting still writes it. Enable the autosave preference above for the old
    behaviour.
  • One click opens. Explorer requests and environments open on a single click; the environment
    being edited is highlighted in the Environments list. Open is gone from their context menus.
  • Context menus are grouped with separators, and Clone sits with Rename and Delete.
  • Release artifact names carry the OS and architecture (for example
    Wirebench-1.1.0-mac-universal.dmg, Wirebench-1.1.0-windows-x64-setup.exe); macOS ships
    universal, Intel and Apple-silicon builds, and Linux gains a .snap. See docs/release.md.
  • Project and workspace format, formatVersion: 2. The per-variable enabled flag above is an
    additive format change: properties stays a plain name -> value map, and a sibling
    disabled: list of names sits beside it, sorted, deduplicated, and omitted entirely when
    empty. A version-1 file (no disabled key) still opens and migrates as "all enabled". A
    1.0.0 build cannot open a project or workspace saved by this version
    — it refuses
    formatVersion: 2 with its existing "created by a newer version of Wirebench" error.
  • Global properties file, version: 2. The same disabled: list, for the global scope's
    properties file in app data.

Removed

  • Opening or creating a project by picking a folder. The Welcome-screen "Open Project…" and
    folder-picker "New Project" flows are gone; a project is now created by name inside a
    workspace, and a folder dialog only appears for linking, importing or exporting a project.
  • The right panel. Its contents moved, each to where it belongs: the request's interface,
    operation, SOAPAction, resolved endpoint (and which layer it came from) and project are now the
    request editor's Details inspector — one of the strip's inspectors, alongside the Auth,
    WS-A, Attachments, Headers, Properties and SSL inspectors that already existed;
    interface-level settings are in the interface tab, project settings and properties in the
    project tab, environments in the Environments view, and the Code view in the right-rail
    slide-over above. view.toggleDetails is gone.

Fixed

  • Mod+S pressed straight after typing saved the envelope as it was before the last keystrokes,
    and Save All could report success while staged request edits stayed unsaved.
  • Mod+S with the caret in the request editor kept saving the first tab opened after switching
    tabs; go-to-definition had the same stale-tab lookup.