diff options
Diffstat (limited to 'PLAN.md')
| -rw-r--r-- | PLAN.md | 21 |
1 files changed, 19 insertions, 2 deletions
@@ -384,8 +384,25 @@ This closes every item from the expanded "worth considering" list. Skipped deliberately (from the research, matches this tool's stated scope): active/passive vulnerability scanning, plugin marketplace, -Collaborator/OAST, team collaboration, CI integration, client TLS -(mutual-TLS) certs, invisible/non-proxy-aware proxying. +Collaborator/OAST, team collaboration, CI integration, +invisible/non-proxy-aware proxying. Client (mutual-TLS) certificates +were later added - see below. + +## Client (mutual-TLS) certificates + +internal/clientcert stores cert/key pairs matched to hosts by the same +substring-or-regex pattern model as scope.Rule (internal/scope) - one +consistent mental model across every "which rule applies to this +host" decision in the tool. A match is looked up in proxy.go's +handleConnect (live proxied HTTPS) and repeat.go's dialForRepeat +(Repeater/Intruder resends), both funneling through +Server.clientCertFor, and passed into the outbound tls.Config's +Certificates field when non-nil. Deliberately add-only in the TUI, no +edit-in-place, same reasoning as scope: delete and re-add covers +changing anything, and it's a rarely-touched, low-cardinality list. +The TUI form takes file paths and reads them once at save time - the +PEM content itself, not the path, is what's stored, so a cert keeps +working even if the original file later moves. ## Licensing, packaging, and browser/mobile support |