HTTP core
RFC 9110, RFC 9111, RFC 9112, and RFC 3986 cover semantics, caching, HTTP/1.1, and URI handling.
Protocol reference
Interceptor tracks standards support explicitly so testers can distinguish full runtime behavior, protocol primitives, and diagnostic-only awareness.
RFC 9110, RFC 9111, RFC 9112, and RFC 3986 cover semantics, caching, HTTP/1.1, and URI handling.
RFC 9113 and RFC 7541 cover HTTP/2 frames, streams, SETTINGS, flow-control accounting, and HPACK.
RFC 9114 and RFC 9204 cover HTTP/3 frames, h3 ALPN, SETTINGS validation, safe frame serialization, and hardened QPACK field representation.
RFC 9000, RFC 9001, and RFC 9002 are tracked for QUIC transport, TLS, and congestion-control expectations.
Implemented or recognized
Core request and response semantics, methods, status codes, and field behavior.
Cache-related passive observations and header analysis.
Proxy parsing, forwarding, chunked bodies, trailers, and connection handling.
Authority, path, query, and URL processing.
Frames, streams, SETTINGS, priorities, and client-side HTTP/2 bridge behavior.
Header compression and decompression for HTTP/2.
Priority header and reprioritization diagnostics.
Extended CONNECT WebSocket bootstrapping over HTTP/2.
QUIC-aware modeling for HTTP/3 features.
TLS and ALPN implications for QUIC/HTTP/3.
Tracked as part of complete QUIC runtime expectations.
HTTP/3 frame and SETTINGS codec support with QUIC varint bounds, reserved SETTINGS rejection, and safe serializers.
HTTP/3 field representation with Huffman literals, dynamic references, safe serialization, pseudo-header validation, and integer bounds checks.
Extended CONNECT WebSocket semantics for HTTP/3 with CONNECT, :protocol websocket, :scheme https, absolute :path, and :authority validation.
Capsule parsing, safe capsule serialization, truncated payload rejection, and HTTP/3 datagram payload mapping.
CONNECT-UDP and MASQUE-like UDP tunnel primitives including HTTPS scheme checks, well-known target validation, IPv6 zone identifiers, and context-id bounds.
WebTransport over HTTP/3 session, stream, datagram, and capsule primitives with SETTINGS dependency validation, initial limit checks, and stream varint hardening.
Runtime TLS support through OpenSSL; MITM remains opt-in.
SNI diagnostics and certificate generation context.
ALPN diagnostics and protocol negotiation visibility.
Detects h3 advertisements in response headers.
DNS HTTPS resource record awareness for ALPN, ECH, and h3 advertisements.
ECH parameter awareness in HTTPS/SVCB records.
Outer ClientHello ECH detection without decryption or bypass.
Support level
Some entries are complete runtime features, some are hardened codecs or protocol primitives, and some are diagnostics. Interceptor records these boundaries deliberately so traffic analysis stays accurate and auditable.
View product features