Skip to content

v4.0.0

Choose a tag to compare

@github-actions github-actions released this 09 Oct 14:17
· 311 commits to main since this release
736f00b

Added

  • WS-Security debugger. The response's WSS inspector now says why a signature, decryption or
    timestamp failed. It shows the part that changed, with its expected and computed digest and the
    transforms used, or a SignatureValue that fails while every part matches. It names the signer token
    or decryption certificate the message asked for and did not find, and the clock skew against the
    timestamp. It also lists the Security header step by step. Preview secured request shows a
    request's secured envelope and its steps before Send (#57).
  • WS-Security from the WSDL's policy. When a WSDL attaches a WS-SecurityPolicy to an operation, the
    request's Auth inspector shows the tokens, the signed and encrypted parts, the algorithm suite and
    whether TLS is required. Apply policy turns it into an outgoing WS-Security configuration in one
    click, and a badge says whether the request satisfies the policy or lists what is still missing (#58).
  • Managed preferences. On a managed machine, a policy.yaml in a system location
    (%ProgramData%\Wirebench, /Library/Application Support/Wirebench or /etc/wirebench) locks the
    proxy, the minimum TLS version, the CA bundle and update checks. Locked settings are read-only in
    Preferences and marked Locked by policy; the user's own values come back if the policy is
    removed (#67).
  • Certificate expiry warnings. Problems warns before a certificate in the workspace expires:
    keystores and the CA bundle are checked on their own, and Check Certificate Expiry also reads
    the chain every TLS endpoint of the open projects presents, from a verified handshake alone; an
    endpoint whose chain doesn't verify is an error. The window is
    Preferences → SSL → Expiry warning (30 days); the SSL inspector uses it too (#70).
  • Secrets from external managers. Map a ${secret:name} to a Vault, AWS, Google Cloud or Azure
    secret, a 1Password item or the keychain, from Secret Sources… in the command palette. Wirebench
    fetches the value at send time with the manager's own CLI and your login, keeps it in memory only
    (Preferences → Secrets, Clear Secret Source Cache) and masks it like any other secret, so
    Toggle Show Secrets in HTTP Log reveals it too. A shared mapping
    is used only after you approve it on this machine, and again after any change; the Problems list
    also flags a request that isn't approved. wirebench run, send, call and mcp fetch the same mappings with
    --trust-secret-sources or --trust-secret-sources-hash, and wirebench secrets list shows each
    secret's source and the mapping's hash (#37).
  • Kerberos authentication. A request, an API, a SOAP interface or endpoint, and a definition
    fetch can authenticate with your Windows sign-in or kinit ticket over HTTP Negotiate, with an
    optional SPN and, on Windows, another account. Kerberos only: nothing falls back to NTLM. The
    WebSocket upgrade and gRPC calls send it preemptively; the CLI and MCP send it too (#40).
  • WS-Trust. Request SAML tokens from a security token service with a username or a client
    certificate, cached for their lifetime; each token request shows in the HTTP Log. wirebench run --verbose reports each token request by host and status, never the token. A token service can
    also be asked with a Kerberos ticket (#41).
  • SAML tokens in outgoing WS-Security. Built from a form (SAML 1.1 or 2.0, optionally signed as
    issuer) or supplied as XML. Token signatures in the HTTP Log are masked (#41).
  • Signatures can refer to a SAML token (holder-of-key) and cover it through the STR-Transform (#41).
  • License binding. A license can be bound to one server. The server mints an id when its database
    is first migrated, and a license that carries a different serverId is refused as wrong-server
    with a message naming both ids. Licenses without the field keep working on any server. The id shows
    as the first line of wirebench-server admin license show and as Server id, with a Copy button,
    on the License tab (#203).
  • Postman environments and globals. Import… reads Postman environment and globals exports
    (Import Postman Environment…, Import Postman Globals…). An environment becomes a workspace
    environment, renamed when the name is taken and never made active; globals merge into Globals.
    Secret-typed values go to the secret store, and nothing that already exists is overwritten. A
    Postman collection's own variables now arrive as project properties instead of being dropped (#64).
  • HAR import. Import… reads HAR 1.1 and 1.2 captures (Import HAR…): one REST API per
    origin, one request per method, path and set of query names. CORS preflights, non-HTTP URLs and,
    unless Include static assets is ticked, static assets are skipped. Recorded responses can be
    left out, written to History at the time they were recorded, or saved as examples. Recorded
    credentials and cookies are never imported: credential-named values are emptied from request
    bodies and masked in examples, in JSON, form and XML alike (#64).
  • .http files. Import… reads .http and .rest request files (Import .http File…)
    into a REST API, with a WebSocket API for WEBSOCKET requests. @variables become project
    properties, response handlers are kept as text under imported-scripts/ and never run, and
    GRAPHQL and GRPC requests are skipped with a warning. When a picked file has
    http-client.env.json or http-client.private.env.json beside it, the dialog offers to import
    those environments too; Import HTTP Client Environments… imports them on their own. Private
    values and credential-named literals become secrets, and an imported environment is never made
    active. Credential-named literals in JSON, form and XML bodies are emptied (#64).
  • OpenCollection. Import… reads OpenCollection 1.x YAML (Import OpenCollection…), as one
    document or as a folder picked by its opencollection.yml. HTTP and GraphQL items become a REST
    API, gRPC items a gRPC API and WebSocket items a WebSocket API, with their folders. Variables
    become project properties and environments workspace environments, never made active; secret and
    credential-named values become secrets. Scripts are kept as text under imported-scripts/ and
    never run, status, response-time and JSON body assertions become request assertions, and a folder
    collection's gRPC API gets the .proto files it names. A folder is read without following links,
    up to 5,000 files and 50 MB. Literal credentials are emptied from bodies, XML included, and from
    the OAuth 2 URLs; a folder's root dropped on its own is refused with a message saying to pick it
    from its folder (#64).
  • Response examples. A REST request can keep recorded responses as examples, up to 5 from a HAR
    import, one per status. The response pane's Examples menu shows one read-only under a banner,
    and Delete example removes it (#64).

Changed

  • Project format 7. Response examples are saved with the project, so the project format is now 7:
    an older Wirebench cannot open a project saved by this one.

Fixed

  • Import cURL warns about a --negotiate account with no password. The preview now notes that the
    Kerberos account needs a password on Windows and is refused on macOS and Linux until you use Clear
    account
    (#272).

  • Update Definition from another host no longer reuses the interface's Kerberos SPN or Basic credentials: a URL on a different origin is fetched with the SPN defaulted to that host, and without the interface's username and password (#271).

  • A REST contract tool no longer asks for a query API key. When the API's auth is a query API
    key, the tool's query argument leaves that parameter out, so the request carries the key once
    instead of key=<argument>&key=<secret> (#225).

  • wirebench mcp on stdio keeps worker output off the protocol stream. A line written to stdout
    by one of the engine's worker threads now goes to stderr with the rest of the server's output, so it
    can no longer corrupt the frames (#182).

  • A partly masked XML value no longer leaves the message unparseable. Where a secret is only part
    of an element's text (<Auth>Bearer <redacted></Auth>), send, call, query, validate and
    history_diff now write the marker as escaped text, so the body and its History entry still parse (#183).

  • Issued-token status while typing. The cached-token line under an issued-token entry reads
    again once you stop editing, not on every keystroke (#279).

  • A WebSocket upgrade refused with 401 drops the OAuth2 token. The next connect fetches a new
    one instead of reusing the stale token until it expires, as a REST 401 already did. A server that
    cannot be reached, a 403, a timeout and a cancel keep the token (#193).

  • gRPC deadline in a run. A unary gRPC call that passes its deadline in a run now errors with
    timeout, as a REST request or a stream does, instead of reporting DEADLINE_EXCEEDED as a result
    that an unasserted call passed with. A status 4 the server returns before the deadline is still a
    result, and sending a call from the app still shows status 4 (#194).

  • Kerberos ticket wait. A slow or unreachable Kerberos server no longer holds a send or a
    Cancel: the wait counts against the request's timeout (the handshake timeout for a WebSocket, the
    deadline for gRPC), Cancel stops it at once, and it fails with timeout and a message naming the
    SPN (#267). A WS-Trust token request with a Kerberos credential does the same: the ticket wait and
    the call to the token service share the request's timeout, and Cancel stops either (#278).

  • OpenCollection proto imports. A folder collection's gRPC API now arrives with its definition
    when its .proto files import other files from the collection's folder: each import is read,
    under the folder first and then beside the importing file. An import that is not there still
    leaves the API with no definition, and the warning now names the import and the file that imports
    it (#247).

  • Imported legacy-project scripts. Importing a legacy SOAP project no longer overwrites a script
    that already exists under imported-scripts/: a clash is saved as -2, -3, … and the import
    report says so (#64).

  • One XML redaction marker. History, the HTTP log and copied commands now write a masked XML
    value, such as a WS-Security password or a secret value found in an XML body, as
    &lt;redacted&gt;, as a masked XML example already did, so a redacted XML document stays well
    formed. Other redaction keeps <redacted>. An XML History entry recorded before this change still
    shows <redacted>, so a diff against a newer entry shows that line as changed (#252).

  • ${ from a contract is sent as written. Wirebench now copies a ${…} from a WSDL or an
    OpenAPI document as $${…}, so it goes on the wire literally and never reads a property, a
    secret or an environment variable. That covers:

    • an XSD fixed or default value, in a generated request or inserted from the form view
    • the SOAP action
    • a WSDL soap:address and its endpoint
    • an OpenAPI path, server and base URL, example or default
    • an OAuth2 token URL, authorization URL or scope, and an API key's name

    This holds in the desktop, send and the contract tools. Validate checks the escaped text as
    the literal value it sends. wirebench generate shows the definition's text unescaped. Anything
    made before this change keeps the unescaped text. Regenerate a request to fix it. Re-import the
    definition to fix an interface's endpoints or an API's servers, base URL and credentials (#223).

  • AsyncAPI text is sent as written. An AsyncAPI import no longer lets a document choose a
    reference. A {name} server variable or channel parameter with no default or enum value now stays
    the literal text {name} instead of becoming the property ${name}, so a document's {token},
    {secret:token} or {#System#NAME} never reads a property, a stored secret or an environment
    variable and sends it to a host the document chose. The import report lists each such slot for you
    to map yourself. Every ${ the document's own text holds is copied as $${: server URLs, channel
    addresses, variable and parameter values, WebSocket binding query and header samples,
    subprotocols, and message examples and samples. Update definition… does not repair an API
    imported before this change, since it keeps the old text as your own edit: import the document
    again (#287).