Repository navigation
v4.0.0
Added
- WS-Security debugger. The response's WSS inspector now says why a signature, decryption or
timestamp failed. It shows the part that changed, with its expected and computed digest and the
transforms used, or a SignatureValue that fails while every part matches. It names the signer token
or decryption certificate the message asked for and did not find, and the clock skew against the
timestamp. It also lists the Security header step by step. Preview secured request shows a
request's secured envelope and its steps before Send (#57). - WS-Security from the WSDL's policy. When a WSDL attaches a WS-SecurityPolicy to an operation, the
request's Auth inspector shows the tokens, the signed and encrypted parts, the algorithm suite and
whether TLS is required. Apply policy turns it into an outgoing WS-Security configuration in one
click, and a badge says whether the request satisfies the policy or lists what is still missing (#58). - Managed preferences. On a managed machine, a
policy.yamlin a system location
(%ProgramData%\Wirebench,/Library/Application Support/Wirebenchor/etc/wirebench) locks the
proxy, the minimum TLS version, the CA bundle and update checks. Locked settings are read-only in
Preferences and marked Locked by policy; the user's own values come back if the policy is
removed (#67). - Certificate expiry warnings. Problems warns before a certificate in the workspace expires:
keystores and the CA bundle are checked on their own, and Check Certificate Expiry also reads
the chain every TLS endpoint of the open projects presents, from a verified handshake alone; an
endpoint whose chain doesn't verify is an error. The window is
Preferences → SSL → Expiry warning (30 days); the SSL inspector uses it too (#70). - Secrets from external managers. Map a
${secret:name}to a Vault, AWS, Google Cloud or Azure
secret, a 1Password item or the keychain, from Secret Sources… in the command palette. Wirebench
fetches the value at send time with the manager's own CLI and your login, keeps it in memory only
(Preferences → Secrets, Clear Secret Source Cache) and masks it like any other secret, so
Toggle Show Secrets in HTTP Log reveals it too. A shared mapping
is used only after you approve it on this machine, and again after any change; the Problems list
also flags a request that isn't approved.wirebench run,send,callandmcpfetch the same mappings with
--trust-secret-sourcesor--trust-secret-sources-hash, andwirebench secrets listshows each
secret's source and the mapping's hash (#37). - Kerberos authentication. A request, an API, a SOAP interface or endpoint, and a definition
fetch can authenticate with your Windows sign-in orkinitticket over HTTP Negotiate, with an
optional SPN and, on Windows, another account. Kerberos only: nothing falls back to NTLM. The
WebSocket upgrade and gRPC calls send it preemptively; the CLI and MCP send it too (#40). - WS-Trust. Request SAML tokens from a security token service with a username or a client
certificate, cached for their lifetime; each token request shows in the HTTP Log.wirebench run --verbosereports each token request by host and status, never the token. A token service can
also be asked with a Kerberos ticket (#41). - SAML tokens in outgoing WS-Security. Built from a form (SAML 1.1 or 2.0, optionally signed as
issuer) or supplied as XML. Token signatures in the HTTP Log are masked (#41). - Signatures can refer to a SAML token (holder-of-key) and cover it through the STR-Transform (#41).
- License binding. A license can be bound to one server. The server mints an id when its database
is first migrated, and a license that carries a differentserverIdis refused aswrong-server
with a message naming both ids. Licenses without the field keep working on any server. The id shows
as the first line ofwirebench-server admin license showand as Server id, with a Copy button,
on the License tab (#203). - Postman environments and globals. Import… reads Postman environment and globals exports
(Import Postman Environment…, Import Postman Globals…). An environment becomes a workspace
environment, renamed when the name is taken and never made active; globals merge into Globals.
Secret-typed values go to the secret store, and nothing that already exists is overwritten. A
Postman collection's own variables now arrive as project properties instead of being dropped (#64). - HAR import. Import… reads HAR 1.1 and 1.2 captures (Import HAR…): one REST API per
origin, one request per method, path and set of query names. CORS preflights, non-HTTP URLs and,
unless Include static assets is ticked, static assets are skipped. Recorded responses can be
left out, written to History at the time they were recorded, or saved as examples. Recorded
credentials and cookies are never imported: credential-named values are emptied from request
bodies and masked in examples, in JSON, form and XML alike (#64). .httpfiles. Import… reads.httpand.restrequest files (Import .http File…)
into a REST API, with a WebSocket API forWEBSOCKETrequests.@variablesbecome project
properties, response handlers are kept as text underimported-scripts/and never run, and
GRAPHQLandGRPCrequests are skipped with a warning. When a picked file has
http-client.env.jsonorhttp-client.private.env.jsonbeside it, the dialog offers to import
those environments too; Import HTTP Client Environments… imports them on their own. Private
values and credential-named literals become secrets, and an imported environment is never made
active. Credential-named literals in JSON, form and XML bodies are emptied (#64).- OpenCollection. Import… reads OpenCollection 1.x YAML (Import OpenCollection…), as one
document or as a folder picked by itsopencollection.yml. HTTP and GraphQL items become a REST
API, gRPC items a gRPC API and WebSocket items a WebSocket API, with their folders. Variables
become project properties and environments workspace environments, never made active; secret and
credential-named values become secrets. Scripts are kept as text underimported-scripts/and
never run, status, response-time and JSON body assertions become request assertions, and a folder
collection's gRPC API gets the.protofiles it names. A folder is read without following links,
up to 5,000 files and 50 MB. Literal credentials are emptied from bodies, XML included, and from
the OAuth 2 URLs; a folder's root dropped on its own is refused with a message saying to pick it
from its folder (#64). - Response examples. A REST request can keep recorded responses as examples, up to 5 from a HAR
import, one per status. The response pane's Examples menu shows one read-only under a banner,
and Delete example removes it (#64).
Changed
- Project format 7. Response examples are saved with the project, so the project format is now 7:
an older Wirebench cannot open a project saved by this one.
Fixed
-
Import cURL warns about a
--negotiateaccount with no password. The preview now notes that the
Kerberos account needs a password on Windows and is refused on macOS and Linux until you use Clear
account (#272). -
Update Definition from another host no longer reuses the interface's Kerberos SPN or Basic credentials: a URL on a different origin is fetched with the SPN defaulted to that host, and without the interface's username and password (#271).
-
A REST contract tool no longer asks for a query API key. When the API's auth is a query API
key, the tool'squeryargument leaves that parameter out, so the request carries the key once
instead ofkey=<argument>&key=<secret>(#225). -
wirebench mcpon stdio keeps worker output off the protocol stream. A line written to stdout
by one of the engine's worker threads now goes to stderr with the rest of the server's output, so it
can no longer corrupt the frames (#182). -
A partly masked XML value no longer leaves the message unparseable. Where a secret is only part
of an element's text (<Auth>Bearer <redacted></Auth>),send,call,query,validateand
history_diffnow write the marker as escaped text, so the body and its History entry still parse (#183). -
Issued-token status while typing. The cached-token line under an issued-token entry reads
again once you stop editing, not on every keystroke (#279). -
A WebSocket upgrade refused with 401 drops the OAuth2 token. The next connect fetches a new
one instead of reusing the stale token until it expires, as a REST401already did. A server that
cannot be reached, a403, a timeout and a cancel keep the token (#193). -
gRPC deadline in a run. A unary gRPC call that passes its deadline in a run now errors with
timeout, as a REST request or a stream does, instead of reportingDEADLINE_EXCEEDEDas a result
that an unasserted call passed with. A status 4 the server returns before the deadline is still a
result, and sending a call from the app still shows status 4 (#194). -
Kerberos ticket wait. A slow or unreachable Kerberos server no longer holds a send or a
Cancel: the wait counts against the request's timeout (the handshake timeout for a WebSocket, the
deadline for gRPC), Cancel stops it at once, and it fails withtimeoutand a message naming the
SPN (#267). A WS-Trust token request with a Kerberos credential does the same: the ticket wait and
the call to the token service share the request's timeout, and Cancel stops either (#278). -
OpenCollection proto imports. A folder collection's gRPC API now arrives with its definition
when its.protofiles import other files from the collection's folder: each import is read,
under the folder first and then beside the importing file. An import that is not there still
leaves the API with no definition, and the warning now names the import and the file that imports
it (#247). -
Imported legacy-project scripts. Importing a legacy SOAP project no longer overwrites a script
that already exists underimported-scripts/: a clash is saved as-2,-3, … and the import
report says so (#64). -
One XML redaction marker. History, the HTTP log and copied commands now write a masked XML
value, such as a WS-Security password or a secret value found in an XML body, as
<redacted>, as a masked XML example already did, so a redacted XML document stays well
formed. Other redaction keeps<redacted>. An XML History entry recorded before this change still
shows<redacted>, so a diff against a newer entry shows that line as changed (#252). -
${from a contract is sent as written. Wirebench now copies a${…}from a WSDL or an
OpenAPI document as$${…}, so it goes on the wire literally and never reads a property, a
secret or an environment variable. That covers:- an XSD
fixedordefaultvalue, in a generated request or inserted from the form view - the SOAP action
- a WSDL
soap:addressand its endpoint - an OpenAPI path, server and base URL, example or default
- an OAuth2 token URL, authorization URL or scope, and an API key's name
This holds in the desktop,
sendand the contract tools. Validate checks the escaped text as
the literal value it sends.wirebench generateshows the definition's text unescaped. Anything
made before this change keeps the unescaped text. Regenerate a request to fix it. Re-import the
definition to fix an interface's endpoints or an API's servers, base URL and credentials (#223). - an XSD
-
AsyncAPI text is sent as written. An AsyncAPI import no longer lets a document choose a
reference. A{name}server variable or channel parameter with no default or enum value now stays
the literal text{name}instead of becoming the property${name}, so a document's{token},
{secret:token}or{#System#NAME}never reads a property, a stored secret or an environment
variable and sends it to a host the document chose. The import report lists each such slot for you
to map yourself. Every${the document's own text holds is copied as$${: server URLs, channel
addresses, variable and parameter values, WebSocket binding query and header samples,
subprotocols, and message examples and samples. Update definition… does not repair an API
imported before this change, since it keeps the old text as your own edit: import the document
again (#287).