Network Channel (network)
- Default Mode:
"block" - Target: All outbound HTTP and HTTPS socket traffic.
network channel intercepts, decrypts, and inspects outbound web traffic originating from your Node.js application process and any third-party dependencies before it reaches the external internet.
How It Works Under The Hood
Whenenvtrap run executes:
- Ephemeral Root CA:
envtrapspins up a 2048-bit RSA Certificate Authority in RAM. The private key never touches the disk. - Loopback Proxy: It starts an in-memory loopback proxy on
127.0.0.1:<random-port>. - Environment Injection: It launches your child application with
HTTP_PROXY,HTTPS_PROXY, andNODE_EXTRA_CA_CERTSpointing to the public CA certificate. - Transparent Decryption: When the application performs HTTPS requests, the proxy negotiates an HTTP
CONNECTtunnel, generates an on-the-fly certificate for the requested domain (e.g.api.stripe.com) signed by the Root CA, and decrypts the stream locally. - Two-Stage Inspection:
- Header Gating: Initial chunks are buffered until the
\r\n\r\nboundary is matched and scanned to prevent early header leaks. - Sliding-Window Streaming: Streaming bodies are scanned using a dynamic overlap window (
Math.min(8192, Math.max(200, maxSecretLength))) to catch secrets split across TCP chunk boundaries.
- Header Gating: Initial chunks are buffered until the
- Upstream Forwarding: If the payload is clean, the proxy establishes a real TLS connection to the remote destination and forwards the data. If a secret is detected, the socket is immediately severed.
What Is Audited
- Request Line & Path: URL paths, search queries, and route parameters (e.g.
GET /api?key=sk_live_...). - Request Headers: All HTTP headers, including
Authorization,Cookie,X-Api-Key, and custom telemetry headers. - Request Body: Streaming payloads, JSON request bodies, form submissions, and GraphQL mutations.
- Encodings: Plaintext, Base64, Hexadecimal, URL percent-encoding (
%2F), and JSON-escaped strings (\/).
Enforcement Modes
- block (Default)
- warn
- off
- Plain HTTP: Responds with an immediate
HTTP 403 Forbiddenresponse (Blocked by envtrap). - HTTPS: The client TLS socket is severed and destroyed immediately (
socket.destroy()). Zero bytes are transmitted upstream to the destination server. - An alert is printed to standard error and recorded in
.envtrap-report.json.
Configuration Example
envtrap.json
Protocol & Streaming Support
- Streaming Uploads & Large Payloads: Streaming bodies are inspected on the fly with sub-millisecond overhead using sliding windows. Memory usage is bounded with a 1 MB diagnostic buffer cap.
- Non-HTTP Raw TLS Protocols: Protocols like PostgreSQL, Redis, or MQTT over TLS do not use HTTP header delimiters (
\r\n\r\n).envtrapsniffs the initial bytes for HTTP method prefixes (GET,POST, etc.); non-HTTP TLS bypasses header buffering to avoid deadlocks. - HTTP/2 & HTTP/3: Node’s forward proxy clients default to HTTP/1.1 over CONNECT tunnels. Native binary-multiplexed HTTP/2 frames and UDP-based HTTP/3 are not intercepted by the loopback proxy.
