Skip to main content

HTTP Forensics

A reproducible toolkit for investigating and documenting HTTP behavior.

HTTP Forensics is a collection of small, self-contained HTTP experiments. Each one starts from a concrete question ("does the client keep the POST after a 301?"), reproduces it against a local server, and records what was actually observed together with the environment it was observed in.

It is not an HTTP client, a mock server or an API test framework. The point is the written-down case, not the tooling around it.

Why HTTP behavior can be surprising

The specification leaves room, history left more, and implementations filled in the rest. A few examples this repository covers:

  • HTTP redirects: 301 and 302 were commonly implemented as "turn POST into GET", while 307 and 308 exist to forbid that. Clients differ, and so do their opt-out flags.
  • HTTP caching: Cache-Control and ETag only matter to something that caches. A client that does not cache just ignores them.
  • HTTP cookies: Path, Secure and HttpOnly are defined by RFC 6265, but clients treat plain-HTTP localhost differently from other hosts.
  • HTTP headers: repeated headers, odd casing and empty values are legal, and different parsers handle them differently.

Blog posts and Stack Overflow answers state these as rules. Usually they are one client's behavior in one version. A case records which.

What a forensic case is

A case follows one line of reasoning:

Case → Experiment → Evidence → Observation

  • Case: a question, with metadata (case.yaml) and an explanation (README.md).
  • Experiment: a script that sets up a local server and drives a real client against it.
  • Evidence: what the script prints, including the requests the server saw.
  • Observation: what you can conclude from that evidence, with the client, server and OS versions written next to it.

Expectations (from a specification, or from experience) are labelled as expectations. An observation is only written down after the case has been run.

Layout

cases/
  redirects/      redirect-post-{301,302,303,307,308}-001
  caching/        caching-etag-304-001, caching-cache-control-001
  cookies/        cookies-attributes-001
  headers/        headers-duplicate-and-empty-001
  responses/      responses-content-type-mismatch-001
  _lib/           shared server and shell helpers
schemas/          JSON Schema for case.yaml
src/              case loading and validation
tests/            tests for the above, plus a check of every case in the repo
docs/             the case format

Each case directory contains case.yaml, README.md, reproduce.sh and the server it uses. The format is described in docs/case-format.md. The requests category is reserved but has no cases yet.

Installing from PyPI

pip install http-forensics installs only the case loader and validator (http_forensics.cases). The cases, servers and reproduction scripts are not part of the package; clone the repository to run them.

Running a case

You need python3 and the client the case uses (all current cases use curl). Servers listen on an ephemeral port on 127.0.0.1; nothing leaves the machine.

cases/redirects/redirect-post-301-001/reproduce.sh

The output starts with the tool versions, then the client's output, then the requests the server saw.

Tests

The tests check the case format and every case in the repository. They need PyYAML, the only dependency.

python3 -m venv .venv
.venv/bin/pip install -e .
.venv/bin/python -m unittest discover -s tests

Contributing

The main contribution is: find one interesting HTTP behavior and turn it into a reproducible case. See CONTRIBUTING.md.

License

MIT

Metadata

Release files for http-forensics 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for http-forensics 0.1.0
File Size Uploaded
http_forensics-0.1.0.tar.gz 7.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for http-forensics 0.1.0
File Interpreter ABI Platform
http_forensics-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 13.6 kB

Release files / http_forensics-0.1.0.tar.gz

Download URL http_forensics-0.1.0.tar.gz
Size 7.6 kB
Tags Source
SHA-256 checksum
How to use checksums
7648231fd9c2bbc7898115cda85b5699441d32914eb82df282210586d7cda68f
BLAKE2b-256 checksum
How to use checksums
fd0b54bac0beee1ac01cf69b919a0bea4d08de63fdb36b34b54bdf28bf1e8292
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 4, 2026.

Transparency log

Release files / http_forensics-0.1.0-py3-none-any.whl

Download URL http_forensics-0.1.0-py3-none-any.whl
Size 6.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
895fd66261a971663aa35ce3e9c37b1a468e5bd0e391edf48b56d82b50986ce7
BLAKE2b-256 checksum
How to use checksums
c438c7c978558edf68060c1c9560c1e4adb4e66d6bb5708e8b015276bcdde146
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 4, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page