Merge pull request #3344 from Tey/master

Fixed doc about domain whitelisting
This commit is contained in:
Maximilian Hils 2018-10-10 17:07:16 +02:00 committed by GitHub
commit 82797efe9f
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -72,8 +72,7 @@ method to do so:
>>> mitmproxy --ignore-hosts ^example\.com:443$ >>> mitmproxy --ignore-hosts ^example\.com:443$
{{< /highlight >}} {{< /highlight >}}
Here are some other examples for ignore Here are some other examples for ignore patterns:
patterns:
{{< highlight none >}} {{< highlight none >}}
# Exempt traffic from the iOS App Store (the regex is lax, but usually just works): # Exempt traffic from the iOS App Store (the regex is lax, but usually just works):
@ -84,15 +83,22 @@ patterns:
# Ignore example.com, but not its subdomains: # Ignore example.com, but not its subdomains:
--ignore-hosts '^example.com:' --ignore-hosts '^example.com:'
# Ignore everything but example.com and mitmproxy.org:
--ignore-hosts '^(?!example\.com)(?!mitmproxy\.org)'
# Transparent mode: # Transparent mode:
--ignore-hosts 17\.178\.96\.59:443 --ignore-hosts 17\.178\.96\.59:443
# IP address range: # IP address range:
--ignore-hosts 17\.178\.\d+\.\d+:443 --ignore-hosts 17\.178\.\d+\.\d+:443
{{< / highlight >}} {{< / highlight >}}
This option can also be used to whitelist some domains through negative lookahead expressions. However, ignore patterns are always matched against the IP address of the target before being matched against its domain name. Thus, the pattern must allow any IP addresses using an expression like `^(?![0-9\.]+:)` in order for domains whitelisting to work. Here are examples of such patterns:
{{< highlight none >}}
# Ignore everything but example.com and mitmproxy.org (not subdomains):
--ignore-hosts '^(?![0-9\.]+:)(?!example\.com:)(?!mitmproxy\.org:)'
# Ignore everything but example.com and its subdomains:
--ignore-hosts '^(?![0-9\.]+:)(?!([^\.:]+\.)*example\.com:)'
{{< / highlight >}}
**Footnotes** **Footnotes**
1. This stems from an limitation of explicit HTTP proxying: A single connection 1. This stems from an limitation of explicit HTTP proxying: A single connection