Serizao/caidoPDF

β˜… 0Forks 0VueGitHub β†—Compare

README

PDF Preview for Caido

Preview PDF HTTP responses directly in the Caido Response viewer, rendered with pdf.js.

CI License: MIT

When an HTTP response is a PDF, this plugin adds a PDF Preview tab to the response pane and renders it inline β€” with selectable text, a thumbnail sidebar, zoom, page navigation and download. The tab appears everywhere Caido shows a response: HTTP History, Replay, Intercept and Sitemap.

Features

  • πŸ“„ Automatic detection β€” the tab only shows up for PDFs (via Content-Type: application/pdf or the %PDF- magic bytes).
  • πŸ”€ Selectable text β€” real pdf.js text layer, so you can select and copy.
  • πŸ–ΌοΈ Thumbnail sidebar β€” click a page to jump to it; the active page is highlighted and kept in sync while you scroll.
  • ⚑ Lazy rendering β€” pages and thumbnails render on demand, so large PDFs stay responsive.
  • πŸ” Zoom & navigation β€” zoom in/out, previous/next page, page counter.
  • πŸ’Ύ Download β€” save the PDF from the response.
  • 🧱 Byte-faithful β€” a small backend plugin reads the real response bytes and transparently handles gzip/deflate encoded bodies.

Screenshots

Screenshots coming soon.

Installation

From the Caido store (recommended)

Once published, open Caido β†’ Plugins β†’ Community Store, search for β€œPDF Preview”, and install it.

From a GitHub release

  1. Download plugin_package.zip from the latest release.
  2. In Caido, go to Plugins β†’ Installed β†’ Install Package and select the zip.

How it works

  • Frontend (packages/frontend) β€” a Vue 3 component registered via sdk.<page>.addResponseViewMode(...). Its when() predicate inspects the raw response so the tab only shows for PDFs. Rendering uses pdf.js with the worker inlined into the bundle (?worker&inline), so there is no separate asset for Caido to serve.
  • Backend (packages/backend) β€” exposes getResponseBodyBase64(id). The frontend can only see response.raw as a JS string, which is unreliable for binary data. The backend reads the real bytes through sdk.requests.get(id).response.getBody().toRaw() and base64-encodes them so the PDF survives the JSON-RPC boundary intact, reporting Content-Encoding so the frontend can decompress. If the backend call fails, the frontend falls back to reconstructing bytes from response.raw.

Development

Requires pnpm and Node 18+.

pnpm install
pnpm build      # -> dist/plugin_package.zip
pnpm watch      # iterative development
pnpm -r typecheck

Project layout

caido.config.ts            # plugin config -> generates manifest.json + zip
packages/
  backend/src/index.ts     # getResponseBodyBase64 RPC endpoint
  frontend/
    src/index.ts           # registers the PDF Preview response view mode
    src/pdf.ts             # pdf.js worker setup + page/text-layer rendering
    src/bytes.ts           # %PDF detection + gzip/deflate normalization
    src/views/PdfPreview.vue
    src/types.ts           # typed backend API surface

Publishing

See PUBLISHING.md for the full release + Caido store submission process (signing key, GitHub release, store PR).

Third-party

This plugin bundles pdf.js (pdfjs-dist), Β© Mozilla, licensed under the Apache License 2.0. See NOTICE.

License

MIT Β© William Le Berre

Contributors

Serizao

Issues