The Authority, Path, Query, and Scheme subtrees describe what URL to send. Fetch is the other axis: what performs the request. The same malicious URL produces different results depending on the client, so the client is worth classifying before choosing a payload.
- Programmatic: a library HTTP client such as
fetch,axios,got, JavaHttpClient, Pythonrequests/httpx, or Gonet/http. It sends the request with no JavaScript execution context and usually no interactive session, so the attack surface is the URL, the redirect policy, and whatever headers the server attaches. - Headless browser: a full browser engine driven server-side (Puppeteer, Playwright, Selenium) for rendering, screenshots, or PDF export. It carries cookies and local storage, runs script, and follows subresource loads, so a single navigation can reuse an authenticated session, execute attacker HTML, and chain requests.
Why the client matters#
A programmatic client that refuses redirects and rejects non-http schemes is a narrow target. A headless browser pointed at the same URL is far wider: it renders attacker markup (so injected HTML and script run in a privileged context), it loads file:// and internal subresources, and it may attach a real session cookie to the request. Deciding which one the application uses tells you whether to invest in raw-byte scheme payloads (programmatic) or in session reuse and rendered-script exfiltration (headless). Host-level tricks such as DNS rebinding apply to both, because both resolve names.