Core Rule Set reads request bodies up to SWWAF_WAF_BODY_LIMIT (closes #116)
check / check (push) Waiting to run
check / check (push) Waiting to run
SWWAF_WAF_BODY_LIMIT (default off, at most 1G) has the Core Rule Set read form data and multipart up to the limit, the rest streaming on, and JSON and XML (with +json, text/json and +xml) no larger than it. The part read is held for the app. A size or time limit met while reading ends the request. Content-Encoding is refused again on these kinds. A body Coraza cannot parse, or a multipart body failing its strict checks, adds 5, but not a multipart body reaching the limit. Coraza is built with no_fs_access, so writes no file. Rule 900300 moves to phase 2. Judgement call: Content-Encoding is refused on a JSON or XML body too large to read, as SPEC.md allows. Model: opus-5-5
This commit is contained in:
@@ -96,6 +96,7 @@ const (
|
||||
wafAnomalyThreshold = "SWWAF_WAF_ANOMALY_THRESHOLD"
|
||||
wafDisabledRules = "SWWAF_WAF_DISABLED_RULES"
|
||||
wafExemptPaths = "SWWAF_WAF_EXEMPT_PATHS"
|
||||
wafBodyLimit = "SWWAF_WAF_BODY_LIMIT"
|
||||
trapPaths = "SWWAF_TRAP_PATHS"
|
||||
errorBurstThreshold = "SWWAF_ERROR_BURST_THRESHOLD"
|
||||
logRemoteURL = "SWWAF_LOG_REMOTE_URL"
|
||||
@@ -580,15 +581,20 @@ func TestCoreRuleSetSettings(t *testing.T) {
|
||||
environment{
|
||||
wafMode: config.WAFModeDetect, wafParanoiaLevel: "4", wafAnomalyThreshold: "10",
|
||||
wafDisabledRules: "942100, 920350", wafExemptPaths: "/api/, /static/",
|
||||
wafBodyLimit: "128K",
|
||||
},
|
||||
config.Config{
|
||||
WAFMode: config.WAFModeDetect, WAFParanoiaLevel: 4, WAFAnomalyThreshold: 10,
|
||||
WAFDisabledRules: []int{942100, 920350},
|
||||
WAFExemptPaths: []string{"/api/", "/static/"},
|
||||
WAFBodyLimit: 128 << 10,
|
||||
},
|
||||
},
|
||||
{
|
||||
environment{wafMode: off, wafAnomalyThreshold: off, wafDisabledRules: ""},
|
||||
environment{
|
||||
wafMode: off, wafAnomalyThreshold: off, wafDisabledRules: "",
|
||||
wafBodyLimit: off,
|
||||
},
|
||||
config.Config{
|
||||
WAFMode: config.WAFModeOff, WAFParanoiaLevel: 1, WAFAnomalyThreshold: 0,
|
||||
WAFDisabledRules: []int{}, WAFExemptPaths: []string{},
|
||||
@@ -601,6 +607,7 @@ func TestCoreRuleSetSettings(t *testing.T) {
|
||||
WAFMode: cfg.WAFMode, WAFParanoiaLevel: cfg.WAFParanoiaLevel,
|
||||
WAFAnomalyThreshold: cfg.WAFAnomalyThreshold,
|
||||
WAFDisabledRules: cfg.WAFDisabledRules, WAFExemptPaths: cfg.WAFExemptPaths,
|
||||
WAFBodyLimit: cfg.WAFBodyLimit,
|
||||
}
|
||||
if !reflect.DeepEqual(got, tc.want) {
|
||||
t.Errorf("%v gave\n%+v\nwant\n%+v", tc.env, got, tc.want)
|
||||
@@ -608,6 +615,15 @@ func TestCoreRuleSetSettings(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestWAFBodyLimitOf1G(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
cfg := fromEnvironment(t, environment{wafBodyLimit: "1G"})
|
||||
if cfg.WAFBodyLimit != 1<<30 {
|
||||
t.Errorf("1G read as %d", cfg.WAFBodyLimit)
|
||||
}
|
||||
}
|
||||
|
||||
func TestInvalidCoreRuleSetSettingStopsTheStart(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
@@ -636,16 +652,28 @@ func TestInvalidCoreRuleSetSettingStopsTheStart(t *testing.T) {
|
||||
`"-942100" is not the id of a Core Rule Set rule, ` +
|
||||
`a whole number such as 942100`,
|
||||
},
|
||||
// The paranoia level, the allowed methods, the headers refused, and
|
||||
// a request with more query parameters than Coraza keeps.
|
||||
// The paranoia level, the allowed methods, the headers refused, a
|
||||
// request with more query parameters than Coraza keeps, and a body
|
||||
// Coraza cannot parse or that fails its strict checks.
|
||||
{wafDisabledRules, "942100,900000", `"900000"` + setupRule},
|
||||
{wafDisabledRules, "942100,900200", `"900200"` + setupRule},
|
||||
{wafDisabledRules, "942100,900250", `"900250"` + setupRule},
|
||||
{wafDisabledRules, "942100,900300", `"900300"` + setupRule},
|
||||
{wafDisabledRules, "942100,900440", `"900440"` + setupRule},
|
||||
{wafDisabledRules, "942100,900450", `"900450"` + setupRule},
|
||||
{
|
||||
wafExemptPaths, "api/",
|
||||
`"api/" is not a path prefix starting with /, such as /assets/`,
|
||||
},
|
||||
{
|
||||
wafBodyLimit, "128KB",
|
||||
`"128KB" is not a size such as 512K, 100M or 5G, or off`,
|
||||
},
|
||||
{wafBodyLimit, "2G", `"2G" is more than 1G, the most Coraza reads`},
|
||||
{
|
||||
wafBodyLimit, "1073741825",
|
||||
`"1073741825" is more than 1G, the most Coraza reads`,
|
||||
},
|
||||
} {
|
||||
t.Run(tc.name+"="+tc.value, func(t *testing.T) {
|
||||
t.Parallel()
|
||||
@@ -2403,6 +2431,7 @@ func TestLogsEachSettingWithItsValue(t *testing.T) {
|
||||
wafAnomalyThreshold: "5",
|
||||
wafDisabledRules: defaultWAFDisabledRules,
|
||||
wafExemptPaths: "",
|
||||
wafBodyLimit: off,
|
||||
trapPaths: "",
|
||||
errorBurstThreshold: "30",
|
||||
logRemoteURL: "",
|
||||
|
||||
Reference in New Issue
Block a user