Initial commit: OpenFUT Bridge
FIFA 23 reverse-engineering proxy and integration scaffold. - Catch-all HTTP proxy that captures all incoming FIFA 23 traffic - Known-route mapper (speculative FUT paths → Core API calls) - Placeholder JSON responses for unmapped endpoints - Admin endpoints: GET /_bridge/captures, GET /_bridge/unknown - Capture persistence to captures/*.json for RE analysis - 4 unit tests passing Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,85 @@
|
||||
# Reverse Engineering Notes — FIFA 23 FUT API
|
||||
|
||||
This document tracks what is known and unknown about EA's FUT API as used by FIFA 23.
|
||||
|
||||
---
|
||||
|
||||
## Status
|
||||
|
||||
🔴 Very early — almost nothing confirmed. All mappings in `src/mapper.rs` are speculative.
|
||||
|
||||
---
|
||||
|
||||
## Known / Suspected Endpoints
|
||||
|
||||
These are guesses based on:
|
||||
- Common FUT API patterns from public research
|
||||
- Observations from older FIFA titles
|
||||
- Community reverse-engineering work
|
||||
|
||||
| Method | Path | Purpose | Status |
|
||||
|---|---|---|---|
|
||||
| `POST` | `/ut/auth` | Authentication / session | Suspected |
|
||||
| `GET` | `/ut/game/fut/user/settings` | User settings | Suspected |
|
||||
| `GET` | `/ut/game/fut/usermassinfo` | Club + profile bulk | Suspected |
|
||||
| `GET` | `/ut/game/fut/squad/active` | Active squad | Suspected |
|
||||
| `GET` | `/ut/game/fut/store/packdetails` | Pack store | Suspected |
|
||||
| `GET` | `/ut/game/fut/transfermarket` | Transfer market | Suspected |
|
||||
|
||||
---
|
||||
|
||||
## Unknown Endpoints
|
||||
|
||||
Run `GET /_bridge/unknown` after a game session to see what new routes appeared.
|
||||
Each entry represents a real FIFA 23 request that hasn't been mapped yet.
|
||||
|
||||
---
|
||||
|
||||
## Request Format Notes
|
||||
|
||||
### Auth
|
||||
|
||||
EA FUT auth appears to use a multi-step token flow:
|
||||
1. EA account auth (OAuth2-style)
|
||||
2. FUT-specific auth with a "nucleus ID"
|
||||
3. Session token issued
|
||||
|
||||
For offline purposes, OpenFUT Bridge returns a static token that satisfies the client.
|
||||
|
||||
### Headers
|
||||
|
||||
Common headers seen in FUT traffic:
|
||||
- `X-UT-SID` — session token
|
||||
- `X-UT-PHISHING-TOKEN` — anti-CSRF token
|
||||
- `Content-Type: application/json`
|
||||
- `X-HTTP-Method-Override` — EA sometimes uses POST + this header instead of DELETE/PUT
|
||||
|
||||
---
|
||||
|
||||
## Tools
|
||||
|
||||
- [mitmproxy](https://mitmproxy.org/) — HTTPS interception
|
||||
- [Fiddler](https://www.telerik.com/fiddler) — Windows-friendly proxy
|
||||
- Wireshark — low-level packet capture
|
||||
- OpenFUT Bridge `captures/` folder — automatic request logging
|
||||
|
||||
---
|
||||
|
||||
## Resources
|
||||
|
||||
- Previous FIFA FUT API research: search GitHub for "fifa-ut-api", "easfc", "futapi"
|
||||
- ea.com documentation: none public
|
||||
- Community wikis: FUT Trading community resources
|
||||
|
||||
---
|
||||
|
||||
## TODO
|
||||
|
||||
- [ ] Capture a real FIFA 23 session via mitmproxy
|
||||
- [ ] Document the auth flow completely
|
||||
- [ ] Map the squad endpoints
|
||||
- [ ] Map the pack opening endpoints
|
||||
- [ ] Map the objectives endpoints
|
||||
- [ ] Map the SBC endpoints
|
||||
- [ ] Map the transfer market endpoints
|
||||
- [ ] Identify which endpoints are critical vs optional
|
||||
Reference in New Issue
Block a user