srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/PLAN.md
diff options
context:
space:
mode:
Diffstat (limited to 'PLAN.md')
-rw-r--r--PLAN.md21
1 files changed, 19 insertions, 2 deletions
diff --git a/PLAN.md b/PLAN.md
index 87c01cf..16a8599 100644
--- a/PLAN.md
+++ b/PLAN.md
@@ -384,8 +384,25 @@ This closes every item from the expanded "worth considering" list.
Skipped deliberately (from the research, matches this tool's stated
scope): active/passive vulnerability scanning, plugin marketplace,
-Collaborator/OAST, team collaboration, CI integration, client TLS
-(mutual-TLS) certs, invisible/non-proxy-aware proxying.
+Collaborator/OAST, team collaboration, CI integration,
+invisible/non-proxy-aware proxying. Client (mutual-TLS) certificates
+were later added - see below.
+
+## Client (mutual-TLS) certificates
+
+internal/clientcert stores cert/key pairs matched to hosts by the same
+substring-or-regex pattern model as scope.Rule (internal/scope) - one
+consistent mental model across every "which rule applies to this
+host" decision in the tool. A match is looked up in proxy.go's
+handleConnect (live proxied HTTPS) and repeat.go's dialForRepeat
+(Repeater/Intruder resends), both funneling through
+Server.clientCertFor, and passed into the outbound tls.Config's
+Certificates field when non-nil. Deliberately add-only in the TUI, no
+edit-in-place, same reasoning as scope: delete and re-add covers
+changing anything, and it's a rarely-touched, low-cardinality list.
+The TUI form takes file paths and reads them once at save time - the
+PEM content itself, not the path, is what's stored, so a cert keeps
+working even if the original file later moves.
## Licensing, packaging, and browser/mobile support