thc202
thc202
ideally the changes should be accompanied with a test(s) that verifies them. IMO it would be better apply the header check to all injections not just OR, this also applies...
The typo is also in the commit message.
The extension can be null there, when disabled.
If you are starting Firefox yourself (instead of starting from ZAP) you might need to set the preference `network.proxy.allow_hijacking_localhost` to `true`, with newer Firefox versions localhost is not proxied without...
I think it is based on the report, the HUD was shown for other addresses/domains just not the tutorial (which is using localhost/127.0.0.1).
The pull request is now updated (after build changes, zaproxy/zaproxy#5302).
Restored the commit lost.
Lets discuss first if we really need more IDs (or how many).
> Is there something we can do to ensure all five enable in unison (as the 4 dependent components already do)? Not without core changes.