summaryrefslogtreecommitdiff
path: root/doc/source/features.rst
diff options
context:
space:
mode:
Diffstat (limited to 'doc/source/features.rst')
-rw-r--r--doc/source/features.rst15
1 files changed, 15 insertions, 0 deletions
diff --git a/doc/source/features.rst b/doc/source/features.rst
index 540e982..f676468 100644
--- a/doc/source/features.rst
+++ b/doc/source/features.rst
@@ -344,6 +344,21 @@ Snuffleupagus can prevent the execution of this kind of file. A good practice
344would be to use a different user to run PHP than for administrating the website, 344would be to use a different user to run PHP than for administrating the website,
345and using this feature to lock this up. 345and using this feature to lock this up.
346 346
347
348.. _mandatory-cert-validation:
349
350Mandatory certificates validation
351^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
352
353It's a common practise to disable `certificate validation <https://en.wikipedia.org/wiki/Transport_Layer_Security>`__
354during development for convenience's sake. Unfortunately, it's equally common
355to forget to turn it back on.
356
357Snuffleupagus can prevent php code from turning off certificate validation
358for anything `cURL <https://secure.php.net/manual/en/book.curl.php>`__-based.
359
360
361
347.. _stream-wrapper-whitelist-feature: 362.. _stream-wrapper-whitelist-feature:
348 363
349Whitelist of stream-wrappers 364Whitelist of stream-wrappers