Repository navigation
Releases: wirebench/wirebench
Release list
v4.0.0
Added
- WS-Security debugger. The response's WSS inspector now says why a signature, decryption or
timestamp failed. It shows the part that changed, with its expected and computed digest and the
transforms used, or a SignatureValue that fails while every part matches. It names the signer token
or decryption certificate the message asked for and did not find, and the clock skew against the
timestamp. It also lists the Security header step by step. Preview secured request shows a
request's secured envelope and its steps before Send (#57). - WS-Security from the WSDL's policy. When a WSDL attaches a WS-SecurityPolicy to an operation, the
request's Auth inspector shows the tokens, the signed and encrypted parts, the algorithm suite and
whether TLS is required. Apply policy turns it into an outgoing WS-Security configuration in one
click, and a badge says whether the request satisfies the policy or lists what is still missing (#58). - Managed preferences. On a managed machine, a
policy.yamlin a system location
(%ProgramData%\Wirebench,/Library/Application Support/Wirebenchor/etc/wirebench) locks the
proxy, the minimum TLS version, the CA bundle and update checks. Locked settings are read-only in
Preferences and marked Locked by policy; the user's own values come back if the policy is
removed (#67). - Certificate expiry warnings. Problems warns before a certificate in the workspace expires:
keystores and the CA bundle are checked on their own, and Check Certificate Expiry also reads
the chain every TLS endpoint of the open projects presents, from a verified handshake alone; an
endpoint whose chain doesn't verify is an error. The window is
Preferences → SSL → Expiry warning (30 days); the SSL inspector uses it too (#70). - Secrets from external managers. Map a
${secret:name}to a Vault, AWS, Google Cloud or Azure
secret, a 1Password item or the keychain, from Secret Sources… in the command palette. Wirebench
fetches the value at send time with the manager's own CLI and your login, keeps it in memory only
(Preferences → Secrets, Clear Secret Source Cache) and masks it like any other secret, so
Toggle Show Secrets in HTTP Log reveals it too. A shared mapping
is used only after you approve it on this machine, and again after any change; the Problems list
also flags a request that isn't approved.wirebench run,send,callandmcpfetch the same mappings with
--trust-secret-sourcesor--trust-secret-sources-hash, andwirebench secrets listshows each
secret's source and the mapping's hash (#37). - Kerberos authentication. A request, an API, a SOAP interface or endpoint, and a definition
fetch can authenticate with your Windows sign-in orkinitticket over HTTP Negotiate, with an
optional SPN and, on Windows, another account. Kerberos only: nothing falls back to NTLM. The
WebSocket upgrade and gRPC calls send it preemptively; the CLI and MCP send it too (#40). - WS-Trust. Request SAML tokens from a security token service with a username or a client
certificate, cached for their lifetime; each token request shows in the HTTP Log.wirebench run --verbosereports each token request by host and status, never the token. A token service can
also be asked with a Kerberos ticket (#41). - SAML tokens in outgoing WS-Security. Built from a form (SAML 1.1 or 2.0, optionally signed as
issuer) or supplied as XML. Token signatures in the HTTP Log are masked (#41). - Signatures can refer to a SAML token (holder-of-key) and cover it through the STR-Transform (#41).
- License binding. A license can be bound to one server. The server mints an id when its database
is first migrated, and a license that carries a differentserverIdis refused aswrong-server
with a message naming both ids. Licenses without the field keep working on any server. The id shows
as the first line ofwirebench-server admin license showand as Server id, with a Copy button,
on the License tab (#203). - Postman environments and globals. Import… reads Postman environment and globals exports
(Import Postman Environment…, Import Postman Globals…). An environment becomes a workspace
environment, renamed when the name is taken and never made active; globals merge into Globals.
Secret-typed values go to the secret store, and nothing that already exists is overwritten. A
Postman collection's own variables now arrive as project properties instead of being dropped (#64). - HAR import. Import… reads HAR 1.1 and 1.2 captures (Import HAR…): one REST API per
origin, one request per method, path and set of query names. CORS preflights, non-HTTP URLs and,
unless Include static assets is ticked, static assets are skipped. Recorded responses can be
left out, written to History at the time they were recorded, or saved as examples. Recorded
credentials and cookies are never imported: credential-named values are emptied from request
bodies and masked in examples, in JSON, form and XML alike (#64). .httpfiles. Import… reads.httpand.restrequest files (Import .http File…)
into a REST API, with a WebSocket API forWEBSOCKETrequests.@variablesbecome project
properties, response handlers are kept as text underimported-scripts/and never run, and
GRAPHQLandGRPCrequests are skipped with a warning. When a picked file has
http-client.env.jsonorhttp-client.private.env.jsonbeside it, the dialog offers to import
those environments too; Import HTTP Client Environments… imports them on their own. Private
values and credential-named literals become secrets, and an imported environment is never made
active. Credential-named literals in JSON, form and XML bodies are emptied (#64).- OpenCollection. Import… reads OpenCollection 1.x YAML (Import OpenCollection…), as one
document or as a folder picked by itsopencollection.yml. HTTP and GraphQL items become a REST
API, gRPC items a gRPC API and WebSocket items a WebSocket API, with their folders. Variables
become project properties and environments workspace environments, never made active; secret and
credential-named values become secrets. Scripts are kept as text underimported-scripts/and
never run, status, response-time and JSON body assertions become request assertions, and a folder
collection's gRPC API gets the.protofiles it names. A folder is read without following links,
up to 5,000 files and 50 MB. Literal credentials are emptied from bodies, XML included, and from
the OAuth 2 URLs; a folder's root dropped on its own is refused with a message saying to pick it
from its folder (#64). - Response examples. A REST request can keep recorded responses as examples, up to 5 from a HAR
import, one per status. The response pane's Examples menu shows one read-only under a banner,
and Delete example removes it (#64).
Changed
- Project format 7. Response examples are saved with the project, so the project format is now 7:
an older Wirebench cannot open a project saved by this one.
Fixed
- Import cURL warns about a
--negotiateaccount with no password. The preview now notes that the
Kerberos account needs a password on Windows and is refused on macOS and Linux until you use Clear
account (#272). - Update Definition from another host no longer reuses the interface's Kerberos SPN or Basic credentials: a URL on a different origin is fetched with the SPN defaulted to that host, and without the interface's username and password (#271).
- A REST contract tool no longer asks for a query API key. When the API's auth is a query API
key, the tool'squeryargument leaves that parameter out, so the request carries the key once
instead ofkey=<argument>&key=<secret>(#225). wirebench mcpon stdio keeps worker output off the protocol stream. A line written to stdout
by one of the engine's worker threads now goes to stderr with the rest of the server's output, so it
can no longer corrupt the frames (#182).- A partly masked XML value no longer leaves the message unparseable. Where a secret is only part
of an element's text (<Auth>Bearer <redacted></Auth>),send,call,query,validateand
history_diffnow write the marker as escaped text, so the body and its History entry still parse (#183). - Issued-token status while typing. The cached-token line under an issued-token entry reads
again once you stop editing, not on every keystroke (#279). - A WebSocket upgrade refused with 401 drops the OAuth2 token. The next connect fetches a new
one instead of reusing the stale token until it expires, as a REST401already did. A server that
cannot be reached, a403, a timeout and a cancel keep the token (#193). - gRPC deadline in a run. A unary gRPC call that passes its deadline in a run now errors with
timeout, as a REST request or a stream does, instead of reportingDEADLINE_EXCEEDEDas a result
that an unasserted call passed with. A status 4 the server returns before the deadline is still a
result, and sending a call from the app still shows status 4 (#194). - Kerberos ticket wait. A slow or unreachable Kerberos server no longer holds a send or a
Cancel: the wait counts against the request's timeout (the handshake timeout for a WebSocket, the
deadline for gRPC), Cancel stops it at once, and it fails withtimeoutand a message naming the
SPN (#267). A WS-Trust token request with a Kerberos credential does the same: the ticket wait and
the call to the token service share the request's timeout, and Cancel stops either (#278). - OpenCollection proto imports. A folder collection's gRPC API now arrives with its definition
when its.protofiles import other files from the collection's folder: each...
v3.1.0
The first release since 2.2.1, carrying both the 3.0 and 3.1 milestones; there is no 3.0.0. The major
version is @wirebench/engine's public exports: the names that
dated from the SOAP-only engine are renamed, and what the new protocol registry replaces is removed,
with no deprecated aliases. Existing projects and workspaces open unchanged, and the wirebench
command line keeps its flags and report shape; the behaviour changes this release does make are listed
under Changed and Fixed. The project format version does move, to formatVersion: 6, because of request
scripts (see Added): a project this build saves opens only in a build that has them. The protocol
modules themselves do not change the project folder format.
Breaking
@wirebench/engine: SOAP-era names renamed.importDefinitionisimportWsdl;ImportSource,
ImportOptions,ImportCacheOptions,ImportProgress,ImportProblemandImportResultgain a
Wsdlprefix (WsdlImportSource, …);summarizeOperationsandOperationSummaryare
summarizeSoapOperationsandSoapOperationSummary;generateRequestandgenerateEmptyRequest
aregenerateSoapRequestandgenerateEmptySoapRequest;toSendInput,ToSendInputArgsand
SendRequestInputaretoSoapSendInput,ToSoapSendInputArgsandSoapSendRequestInput;
SendAttachmentOptionsisSoapAttachmentOptions. Signatures are unchanged.@wirebench/engine: exports removed.prepareSendandPreparedSend(send through
createRunSender);assertSupportedKindandapiKindOf(askProtocolRegistry.status);
RequestDef(it was an alias ofSoapRequestDef);scriptTypesFor;ScriptProtocol(it is
string); andRequestScriptTypes.soap, which is now the opaquebinding.@wirebench/engine:protocolis astring.RequestResult.protocol,
AssertionSubject.protocolandScriptedRequest.protocolwere the union'soap' | 'rest' | 'grpc'.
The JSON report'sprotocolfield is typed the same way; the values a run writes are unchanged.@wirebench/engine: one send path.ProtocolRun.sendis replaced byopen, which starts a send
and hands back an exchange (its events,push,halfClose,close,cancelandresult), and
resolve, which gives what a send would send with nothing connected.RunContext.host, aSendHost,
replacesgetSecret,proxyFor,onSecretValue,fetchTokenandtokenSource, and also carries
what a host can lend a send: TLS anchors and identities, preferences, cookies, a contract check and
gRPC schemas.prepareRest,prepareSoapandprepareGrpc, the modules' own prepare functions (never exports of
the main entry), are removed.openExchange,
resolveExchangeandSendHostare added, with the types around them (ExchangeHandle,
ExchangeOptions,SendFailure). The desktop, the command line and MCP all send through them.
packages/engine/README.md has the full tables and a
before and after for the two changes that need more than a rename. The package's subpaths (./xml,
./rest, ./json, ./grpc, ./asyncapi, ./snapshot, ./detect) are unchanged.
Added
sendbaseline check.send(the MCP tool, andwirebench send --baseline) compares the
response with the request's golden and returns the differences (#218).wirebench run --update-baselinesaves each changed response as its request's golden, keeping
its ignore rules, and lists the files it wrote (#217).- Cookie jar. Cookies responses set go into a jar per workspace, kept across restarts (encrypted
with the system keychain) except session cookies. A REST request with Send cookies on sends the
matching ones, per redirect hop. View → Show Cookies opens a manager to view, add, edit and
delete them, and the response's Cookies tab says what was stored or ignored.wirebench run
keeps a jar for the run (#44). - Current values. Every variables table has a Current column: a session-only value that
replaces the committed one for sends and previews. The store is memory only; a request that is
sent records what it sent, as for a committed value, so keep credentials in${secret:…}(#44). - HTML preview. The Preview tab renders an HTML response or webhook capture as a static page in a
sandboxed frame: no scripts, forms, navigation or network (#48). wirebench run --baselinecompares each response with its committed golden and fails on a
semantic difference;--require-baselinemakes a missing golden an error (#36).- Contract operations as MCP tools (#33).
wirebench mcplists every imported SOAP operation and
OpenAPI endpoint as a tool of its own, with a JSON Schema built from the XSD or the OpenAPI schemas.
An agent calls it with JSON; Wirebench builds the envelope or request, sends it under the interface's
or API's endpoint, auth and secrets, records it in History, and returns the response as JSON. The
list follows the project as it changes, at most 128 tools are served, and--toolspicks the
interfaces and APIs.wirebench callruns the same from a terminal, andoperationsrows show each
operation's tool name. - An Assertions tab on every editor. The REST, SOAP, gRPC and WebSocket editors have an Assertions tab.
Every editor Send checks the request's assertions and shows the result in the response pane's
Assertions tab; callback assertions are still checked in runs and sequences only (#192). - A WebSocket request carries
assertions:(part offormatVersion: 6). Runs,sendand MCPsend
check them, and--require-assertionssends a WebSocket request that has them (#192). - A landing site. https://wirebench.github.io/wirebench/ now has a home page, a features page and a
download page built from the latest release; the user guide moved to
https://wirebench.github.io/wirebench/docs/. - Protocol modules in the engine. SOAP, REST, gRPC and WebSocket each sit behind one interface,
held in a registry, so the loader, the writer, the run loop and the script host no longer branch on
the protocol (ADR-0017, #184). Two
things follow for a project. An interface or API of a kind this build does not know no longer stops
the project from opening: it is reported as acontainer-unsupportedproblem, the rest of the
project loads, and a save leaves that container's files exactly as they were. Andwirebench send
names such a container, with the reason, where it answered that no request matched. The registry
also carries feature switches for each protocol and for scripts; every one is on, and nothing in the
app or the command line turns one off yet.@wirebench/engineexports the module interface for
Wirebench's own use, tagged@internal: it is not a plugin API. - Agents over MCP, and the same verbs in the terminal.
wirebench mcpserves one project to a
coding agent as MCP tools —import,operations,generate,send,validate,query,
history_list,history_diff— over stdio, or over Streamable HTTP on 127.0.0.1 behind a bearer
token.sendneeds--allow-send(and--envlimits where it goes),importneeds
--allow-write, and every result is redacted, secrets included. The same capabilities are CLI verbs
(wirebench import,operations,generate,send,validate,query,history list|diff),
with--jsonfor the exact result. A send from the terminal or an agent lands in the desktop's
History, and an open History panel refreshes when another process writes the file (#32). sendtakes WebSocket requests.wirebench sendand the MCPsendtool send a saved WebSocket
request aswirebench rundoes: open the socket, send the saved messages, wait for a reply, close,
and return the frames collected, masked. A session with no reply before the timeout fails with
timeout, returning no frames and writing no History; a server that refuses or cannot be reached
fails withws-handshake-refused. The send lands in the desktop's History as the app's own
WebSocket sessions do, taggedcliormcp.operationslists saved WebSocket requests by path. A name a REST and a WebSocket request
share is now ambiguous where it used to resolve to the REST request; gRPC requests are still refused.
A saved WebSocket request without assertions errors under--require-assertionsin a run (#184).- Streaming requests run.
wirebench runwith no selector,wirebench run --sequence, and a
sequence in the app now send WebSocket, streaming gRPC and Server-Sent Events requests, which a run
used to skip or refuse. A gRPC client or bidirectional stream sends its saved messages in order and
half-closes; a WebSocket request sends its saved messages and closes after the last reply; an event
stream is read until it ends. The run's timeout bounds every one of them, and a stream it cuts fails
withtimeoutinstead of passing. Everything received is what the request's assertions and a
sequence's transfers read. A new error code,exchange-not-streaming, answers a message pushed to,
or a half-close asked of, a send that takes none (#184). - Request scripts. A SOAP, REST or gRPC request can have a pre-request script, which runs just
before the send and can change it (sign the body, add a header, fill in a field), and a
post-response script, which checks the response with tests and keeps values for later requests.
Scripts are TypeScript typed from the request's own contract — the operation's XSD elements, its
OpenAPI schemas or its.protomessages — so the Scripts tab completes the message and a wrong
path is an error before anything is sent. The response's Script tab shows the tests and the log.
A value a script keeps is read by later requests as${#Sequence#name}: in a sequence run, in
`...
v2.2.1
Fixed
- The update check no longer offers an older release. A build newer than the latest published
release — 2.2.0 while 1.1.0 was still the newest public one — was offered that older release as an
"update", and Download would have installed it over the running version. An update is now
offered only when the release is newer than the one running.
v2.2.0
Added
-
WebSocket request kind. A fourth container beside SOAP, REST and gRPC, in the same project, workspace,
environments, history and search. New WebSocket API… takes aws://orwss://URL; a request under it
connects with headers, query parameters, subprotocols, the shared auth kinds that are a header or query
value, the resolved proxy, a client certificate and the custom CA bundle. Every frame — sent or received,
text or binary, control or data — appears on a live timeline as it arrives, with a pretty-printed view for
JSON or XML text one toggle from the raw bytes. While connected, the composer sends a typed or saved
message (${…}properties expand at send time); Disconnect closes with a chosen code (1000 or
3000–4999) and reason, and the close frame and every ping/pong show as control rows. The handshake is one
HTTP Log entry (GET, its headers, the101or the refusal, timing and TLS); the session appears in
History when it closes, capped to its first 400 and last 100 frames within 1 MB — History's own re-send
stays offered for a SOAP entry only.kind: websocketwrites under the existingformatVersion: 3; a
project without a WebSocket API is byte-identical to before. See
docs/specs/2026-09-19-websocket-request-kind-design.md
and the update to ADR-0007. -
Fleet-ready releases. An MSI installer for Windows x64 and arm64, for Intune and other fleet
tools (msiexec /qn); a CycloneDX SBOM with every release; build and SBOM attestations on tagged
releases, checked withgh attestation verify. Windows signing through SignPath Foundation is wired
into the release workflow and switches on with its secrets. Silent installs and download
verification are on the install page, and the site has a code-signing policy. -
User guide. A documentation site at https://wirebench.github.io/wirebench/: install and first run on
macOS, Windows and Linux, a ten-minute walkthrough, a guide for every feature area, a command and
shortcut reference generated from the app, troubleshooting and an FAQ. It is published frommainon
every push, and its screenshots are shot from the app by the e2e suite. -
Switching guide. A Switching section on the site, one page per source — Postman collections,
legacy SOAP projects, OpenAPI and Swagger, and cURL commands — each saying what carries over, what
does not, and where the equivalent lives in Wirebench. -
cURL import reads
--json,-Gand-I.--jsonbecomes a JSON body with its two headers,
-Gmoves the data into query rows, and-Iasks for HEAD. -
CLI runner:
wirebench runandwirebench secrets list. A new package,@wirebench/cli
(binarywirebench), runs the requests already saved in a project from a pipeline:status,
soap-fault,match(XPath/XQuery/JSONPath),schemaandslaassertions declared per request;
cli,junit,jsonandhtmlreports; secrets resolved fromWIREBENCH_SECRET_<NAME>/
WIREBENCH_SECRET_<REF>environment variables, never from the desktop's keychain-backed store;
and exit codes a pipeline can branch on (0 pass, 1 assertion failed, 2 usage/load, 3 run error,
130 interrupted). gRPC unary and OAuth2 client-credentials are not in this release. See
docs/cli.mdand
docs/specs/2026-09-18-cli-runner-design.md.Project format moves to version 4. Saving a request now carries an optional
assertions:
list and an optional…Envname beside apasswordRef/tokenRef/valueRef/clientSecretRef.
Both are additive, and a version-3 project migrates in memory without any data moving — but
because this format drops unknown keys on save, saving a project with this version writes
formatVersion: 4, and an older Wirebench refuses to open it (format-too-new). Everyone
working on a project a 2.2+ build has saved needs to be on 2.2 or later too. -
CI recipes for the runner.
@wirebench/cliand@wirebench/engineare published to npm; a
container image is published toghcr.io/wirebench/wirebench-cli(linux/amd64+
linux/arm64); a GitHub Action (wirebench/wirebench/action@<tag>) and a GitLab template
(templates/gitlab/wirebench.gitlab-ci.yml) wrap them. All four ways to run in CI map secrets
toWIREBENCH_SECRET_<NAME>the caller sets — none of them holds or asks for one itself. See
"Run in CI" and
docs/specs/2026-09-19-ci-recipes-design.md.
Publishing itself waits on the first tagged release after the npm organisation and the GHCR
package's visibility are set up (see "Before the first publishing
release"). -
HTTP Log: rows kept and Preserve log. The number of rows kept is a setting (Preferences › Behaviour,
100–5000, default 500). Preserve log keeps the rows in memory across closing or switching a workspace;
it is never written to disk and is off again at every launch. -
HTTP Log: compare two rows. Cmd/Ctrl+click a second row to compare the two — a summary of each,
request and response headers marked added/removed/changed, and request and response bodies side by
side (pretty-printed when both are JSON or both XML). Escape goes back to one row. -
HTTP Log: waterfall. A Waterfall column shows each row's start and duration across the rows shown,
split into connect, TLS, wait and download (hover for the breakdown; hidden while a row is selected); the
Timing tab notes a reused connection. -
HTTP Log: search, a Name column and sort. Search matches headers, bodies (first 256 KiB) and the
request name, with regex and match-case toggles; a Name column shows the saved request; click Time,
Name, Status, ms or Size to sort. -
HTTP Log: Export HAR. Saves the rows the filter shows, in display order, as a HAR 1.2 file;
headers, URL parameters, WS-Security passwords and JSON/form secrets are always masked, whatever
the show-secrets toggle says. Failed sends carry an_error, truncated bodies_truncated. -
HTTP Log row menu. Right-click a row, press its detail's ⋯ button or press Shift+F10 on the selected
row to copy it as cURL (POSIX or PowerShell) from what was sent, copy its URL, request or response headers
or response body, resend the saved request as it is now, or open the request. -
HTTP Log: failures before the request is built. A send that fails before the request is built (invalid URL,
proxy lookup, OAuth2 token fetch) now appears as a "Failed · before send" row, and its detail says the request
never went on the wire. -
Importing a legacy single-XML SOAP project. Import Legacy SOAP Project… (or Legacy SOAP project in
Import…, which also detects the file) brings a whole project file from an older SOAP workbench into a
Wirebench project. It carries across the SOAP interfaces with their endpoints, every saved request (envelope
unchanged, and gzip-compressed envelopes decoded), usernames, timeouts, encodings, project properties, and
environments with their endpoint overrides. Each interface resolves from the definition the file carried, so
the import works offline and the project reopens offline. What does not come across is listed in a report you
can copy: passwords (to be re-entered), test suites, mock services, REST services, WS-Security and auth
profiles. Scripts are kept, never run, underimported-scripts/. Picking such a file as a plain WSDL now says
which format to choose instead of failing partway through. -
Completion in the gRPC message editor. Typing a key in the Message tab offers the fields of the message
the cursor is in — not just the method's request type, so a nested field's own fields are offered inside it,
and a repeated field's items are offered like the field itself. Accepting one writes the key with an empty
value of the right JSON shape, and the suggestion carries the declared type, the field's.protocomment and,
for an enum, its values. A key the object already holds is not offered, nor is the rest of aoneofwhose
member is already written. Other JSON editors in the app are unchanged. See
docs/specs/2026-09-18-grpc-message-completion-design.md. -
gRPC live streaming and interactive bidirectional send. A streaming call now shows itself while it runs:
the response pane raises its tabs as soon as the call opens, the server's initial metadata appears when its
headers arrive, and each reply is appended as it is decoded rather than all of them at the end. For a method
whose client streams, Open stream starts the call and leaves the request side open — a composer under the
response pane sends one more message at a time and Half-close stops sending without ending the call, so a
bidirectional method can be held as a conversation. Every message pushed by hand is part of the exchange that
is recorded, inrequestMessagesand in the raw request bytes. See
docs/specs/2026-09-18-grpc-live-streaming-design.md. -
gRPC server reflection. Point Wirebench at a running gRPC server and it describes itself: the Import
dialog's gRPC format gains a Server tab taking an address, the reflection version (automatic by default —
grpc.reflection.v1, falling back tov1alpha) and whether to ask a server whose certificate does not verify.
What comes back builds the same folder-per-service, request-per-method API a.protoimport builds, and is
cached with the project as the descriptor set the server sent. The gRPC API tab's Definition card gains
Refresh from server: asking again adds a request for a method the server has gained and badges one wh...
v2.1.1
Changed
- Documentation. The README's screenshots are re-shot against 2.1.0: the explorer as it looks
now (fold chevrons, the method column, the tighter nesting) and the unified Import… dialog in
place of the retired Import WSDL… entry. The capture spec dismisses the folder watcher's
"changed on disk" banner first, so a picture no longer documents a bar the reader will not see.
v2.1.0
Added
-
Shared workspaces. A workspace can now be shared with a team: Share this workspace… turns
it into a git repository (remote optional, branch defaultmain) or moves it into a synced
folder; Join shared workspace… clones one from a URL or opens an existing clone or synced
folder. Every save becomes a commit with a generated message; a status-bar Sync badge and panel
pull, push, fetch and show recent commits; a conflict resolver lists each conflicted entity with
Keep mine / Keep theirs / Open file. Environments now travel with the workspace like
everything else. Seedocs/collaborate.mdand
ADR-0008. -
Not on this machine. In a shared workspace, a request field whose secret ref has no value on
this machine shows Not on this machine with an Enter… button; the value you type is stored
locally under the same ref, so the shared files and your teammates' files never change. -
Git preferences. Preferences → Git shows the git executable Wirebench will run and its
version, with Locate… to pick a specific binary and Clear to return to automatic discovery.
Changed
- Workspace format
3.activeEnvironmentIdmoves out ofworkspace.yamlinto a
machine-locallocal.yaml(it was never meant to be shared between members), andwrittenByis
dropped from the manifest entirely. A version-2 workspace still opens and lifts its active
environment on first open; a version-3 workspace is refused by an earlier build with the existing
"created by a newer version of Wirebench" error. A shared workspace also gains a machine-local
share.yaml(remote, branch and sync settings) alongside it, never written into the shared tree.
Known limitations
-
Line-level merges. Two edits to the same request's envelope (or any other single file) can
still conflict at the line level even though one file is one entity; the conflict resolver
covers this today, a YAML-aware merge driver is a listed follow-up. -
No shared secret values. Secret refs travel with a shared workspace; the values behind them
stay per member. Shared, encrypted secret values are a follow-up for Wirebench Server. -
Not every missing secret raises the named error. A missing endpoint password or WSDL-import
password fails at send time with a message naming the field; a missing keystore passphrase,
proxy password, or WS-Security secret fails silently instead — check the field for Not on this
machine. -
Synced folders have no merge. A
foldershare has no Sync control; two members saving the
same file race on whatever the folder's own sync tool does about it, usually last-write-wins.
v1.1.0
Added
-
Workspaces. Wirebench now groups any number of projects into a workspace stored under
Electron'suserData, with no folder to manage — the launch picker creates or opens one by
name. A workspace holds its own environments, shared by every project it contains, with a
${#Workspace#…}property scope; an interface's effective endpoint is the workspace
environment's override, falling back to a linked project's own (name-matched) environment,
then the interface's default. Link existing project folder… and Import project folder…
bring an external project in for teams that keep it in git; Export project… writes it back
out. Removing a project is trash-only and confirmed; a linked project's folder is never
touched. Tabs, the explorer, and History span every project in the open workspace, and the
last-open workspace (with its tab set) reopens on launch. -
Environments view. Environments moved out of the right panel into their own left-menu view
(activity bar → Environments,view.showEnvironments), listing Globals, the workspace and
every environment; opening one shows a variables table and an endpoint-overrides table, Postman
style, instead of a grid. -
Per-variable enabled checkbox. Every property scope — project, environment, workspace,
workspace environment, and globals — can now disable one variable without deleting it; an
unticked variable's value stays on disk but is skipped during resolution, falling through to
the next scope down. -
Project tab. Selecting a project row opens it as a normal pinned tab instead of a side
panel, showing the project's own settings and properties. -
Code slide-over. A right icon rail replaces the old right panel; its one icon today opens a
slide-over showing the active request ascurl(view.toggleCode,Mod+Alt+B, the shortcut
freed by the removed Details-panel toggle), closed by Escape or the rail icon again. -
Collapsible, resizable panels. The sidebar, console and Code slide-over can each be
collapsed and resized by dragging their handle, by the chevron in the panel's own header or its
status-bar toggle, or by double-clicking the handle to snap collapsed or restored. Dragging the
sidebar's or the console's handle past the panel's minimum closes it, and dragging the same
handle back out reopens it; sizes and collapsed state persist across a relaunch. -
Environment selector in the title bar. The active-environment switcher moved from the status
bar to the top-right of the title bar, beside the theme toggle. -
Preferences dialog. Settings open as a modal dialog from the activity bar's foot (or
preferences.open) instead of a sidebar list plus an editor tab. -
Per-tab save.
Mod+Ssaves the request tab in front of you, and each tab shows its own
unsaved dot; Save All (Mod+Alt+S) saves every open project. The project tab shows
Unsaved changes / Saving… / Saved beside the project name. -
Autosave preference. Preferences → Editor → Autosave projects turns autosave back on;
turning it on mid-session writes any outstanding edit straight away. -
Code panel highlighting. The
curl/ PowerShell preview is rendered as highlighted code,
with flags, strings and heredoc bodies told apart.
Changed
- Saving is manual by default. Edits stay in the open project until you save; closing a
project or quitting still writes it. Enable the autosave preference above for the old
behaviour. - One click opens. Explorer requests and environments open on a single click; the environment
being edited is highlighted in the Environments list. Open is gone from their context menus. - Context menus are grouped with separators, and Clone sits with Rename and Delete.
- Release artifact names carry the OS and architecture (for example
Wirebench-1.1.0-mac-universal.dmg,Wirebench-1.1.0-windows-x64-setup.exe); macOS ships
universal, Intel and Apple-silicon builds, and Linux gains a.snap. Seedocs/release.md. - Project and workspace format,
formatVersion: 2. The per-variable enabled flag above is an
additive format change:propertiesstays a plainname -> valuemap, and a sibling
disabled:list of names sits beside it, sorted, deduplicated, and omitted entirely when
empty. A version-1 file (nodisabledkey) still opens and migrates as "all enabled". A
1.0.0 build cannot open a project or workspace saved by this version — it refuses
formatVersion: 2with its existing "created by a newer version of Wirebench" error. - Global properties file,
version: 2. The samedisabled:list, for the global scope's
properties file in app data.
Removed
- Opening or creating a project by picking a folder. The Welcome-screen "Open Project…" and
folder-picker "New Project" flows are gone; a project is now created by name inside a
workspace, and a folder dialog only appears for linking, importing or exporting a project. - The right panel. Its contents moved, each to where it belongs: the request's interface,
operation, SOAPAction, resolved endpoint (and which layer it came from) and project are now the
request editor's Details inspector — one of the strip's inspectors, alongside the Auth,
WS-A, Attachments, Headers, Properties and SSL inspectors that already existed;
interface-level settings are in the interface tab, project settings and properties in the
project tab, environments in the Environments view, and the Code view in the right-rail
slide-over above.view.toggleDetailsis gone.
Fixed
Mod+Spressed straight after typing saved the envelope as it was before the last keystrokes,
and Save All could report success while staged request edits stayed unsaved.Mod+Swith the caret in the request editor kept saving the first tab opened after switching
tabs; go-to-definition had the same stale-tab lookup.