Skip to content

Commit

Permalink
Update Changelog-1.9.3.rst
Browse files Browse the repository at this point in the history
  • Loading branch information
unbit committed Mar 29, 2013
1 parent 24c84e0 commit 384f422
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion Changelog-1.9.3.rst
Original file line number Diff line number Diff line change
Expand Up @@ -69,7 +69,7 @@ Albeit it is the most secure approach, two new options --immediate-uid and --imm
Setting them on top of your vassal file will force the instance to setuid()/setgid() as soon as possibile and without the (theoretical) possibility to override them.

The word "theoretical" here is the key, you always need to remember that a security bug in uWSGI could allow a malicious user to change privileges, so if you really
care security (or do not trust uWSGI developers ;) always drop privileges before teh vassal/instance is spawned (like in standard tyrant mode)
care security (or do not trust uWSGI developers ;) always drop privileges before the vassal/instance is spawned (like in standard tyrant mode)

Honouring symlinks in tyrant mode
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
Expand Down

0 comments on commit 384f422

Please sign in to comment.