Skip to content

Request-body replacement

Request-body rules replace a complete body or apply bounded global ECMAScript regular expression replacement to eligible POST, PUT, or PATCH XHR requests. They use the runtime-owned TLS proxy.

  • Full body replace, or
  • Bounded global ECMAScript regex replace on the body.
  • Bounded UTF-8 JSON, form-encoded, or textual bodies.
  • Unsupported framing, encoding, or signatures are rejected.
  • Requires the native runtime to be started. Without the runtime, request-body rules report unsupported.
  • Activation is capability-based and cannot compose with another controlling proxy, PAC, extension, or enterprise policy.
  • Where the required capabilities are absent, activation reports unsupported; Linux and Windows may still verify, edit, import, export, and dry-run request-body rules.
  • Requires the device-local CA trust installed via rogatio runtime install. CA trust installation requires elevated privileges: Linux (sudo), macOS (keychain password), Windows (Administrator). On incapable platforms the install completes without CA trust. See Local runtime.
  • Observed bodies are processed in-process only and never persisted, logged, exported, or transferred through native messaging.