Files
OpenFUT-Bridge/TODO.md
T
funman300 f3ff291ff8 Phase 8 (Bridge): SID/phishing header passthrough, updated TODO
- proxy.rs: forward_to_core() now accepts the incoming headers vec
  and passes X-UT-SID, X-UT-PHISHING-TOKEN, and X-Request-ID through
  to Core on every mapped request (#19, #20)
- TODO.md: mark #15-#20 as complete with implementation notes;
  update test counts; clean up duplicate #15 entry

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-25 16:42:09 -07:00

3.0 KiB

OpenFUT Bridge — TODO

Reverse Engineering

  • #1 Set up mitmproxy and capture a real FIFA 23 FUT session
  • #2 Document all observed endpoints in docs/endpoint-map.md
  • #3 Document FIFA 23 auth flow (token format, headers, session lifecycle)
  • #4 Document request body formats for auth, squad, packs
  • #5 Identify which endpoints are mandatory vs optional for FUT to load
  • #6 Test hosts-file redirect approach on PC
  • #7 Research certificate pinning in FIFA 23 PC build
  • #8 Test RPCS3 network proxy configuration
  • #9 Document response formats EA uses (some differ from request format)
  • #10 Identify any binary/protobuf endpoints (most are JSON but verify)

Proxy

  • #11 Add TLS support (self-signed cert) so FIFA 23 connects via HTTPS → TLS_ENABLED=true generates cert at startup via rcgen; uses tokio-rustls → Cert covers localhost, 127.0.0.1, fut.ea.com, utas.mob.v4.fut.ea.com
  • #12 Add replay CLI: openfut-bridge-replay captures/some_file.json [bridge-url] → Accepts single file or entire captures/ directory → TLS: danger_accept_invalid_certs=true so self-signed certs work
  • #13 Add DELETE /_bridge/captures to wipe capture folder
  • #14 Add capture deduplication (same method+path within 1 second)
  • #15 Add request diff tool: GET /_bridge/captures/diff?a=<id>&b=<id> → Reports method/path/status changes, header diffs, JSON body key-level diff

Mapper

  • #16 Implement auth endpoint mapping + response shaping → src/shaper.rs wraps Core /auth/local response in FUT auth envelope → Includes sid, phishingToken, persona, pid, userAccountInfo
  • #17 Map squad read/write endpoints → GET /ut/game/fut/squad/active → Core GET /squad → PUT /ut/game/fut/squad/active → Core POST /squad
  • #18 Map pack details endpoint → GET /ut/game/fut/store/packdetails → Core GET /packs → Response shaped into FUT purchasedPacks envelope
  • #19 Add X-UT-SID session header pass-through to Core → Forwarded verbatim on every mapped Core request
  • #20 Add phishing token passthrough → X-UT-PHISHING-TOKEN forwarded on every mapped Core request

Admin UI

  • #21 Build a simple web dashboard for viewing captures (GET /_bridge/admin) → Auto-refreshes every 10s; shows stats, endpoint table, recent captures
  • #22 Add endpoint status page (GET /_bridge/status) → Reports each unique endpoint as mapped/known/unknown
  • #23 Add live capture stream via SSE (GET /_bridge/captures/stream) → event: capture events pushed on each new capture

Testing

  • #24 Add test for placeholder response format
  • #25 Add integration test that fires real HTTP at the Bridge → 13 tests: health, placeholder, captures CRUD, status, TLS cert gen
  • Shaper unit tests (4) — auth envelope shape, dispatch, passthrough, market
  • Mapper unit tests (6) — auth, market, events, squad PUT, unknown, trailing slash