Core Rule Set reads request bodies up to SWWAF_WAF_BODY_LIMIT (closes #116)
check / check (push) Waiting to run
check / check (push) Waiting to run
SWWAF_WAF_BODY_LIMIT (default off, at most 1G) has the Core Rule Set read form data and multipart up to the limit, the rest streaming on, and JSON and XML (with +json, text/json and +xml) no larger than it. The part read is held for the app. A size or time limit met while reading ends the request. Content-Encoding is refused again on these kinds. A body Coraza cannot parse, or a multipart body failing its strict checks, adds 5, but not a multipart body reaching the limit. Coraza is built with no_fs_access, so writes no file. Rule 900300 moves to phase 2. Judgement call: Content-Encoding is refused on a JSON or XML body too large to read, as SPEC.md allows. Model: opus-5-5
This commit is contained in:
+2
-2
@@ -1,7 +1,7 @@
|
||||
#!/bin/sh
|
||||
# script/build: build bin/smallwebwaf on the host, with Go installed, for
|
||||
# working on the code by hand. The version it reports comes from git, as
|
||||
# in script/docker.
|
||||
# in script/docker, and the no_fs_access tag is the Dockerfile's.
|
||||
set -eu
|
||||
|
||||
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
||||
@@ -11,7 +11,7 @@ main() {
|
||||
cd "$ROOT"
|
||||
version="$(git describe --tags --always --dirty 2>/dev/null || true)"
|
||||
[ -n "$version" ] || version="unknown"
|
||||
go build -trimpath -ldflags "-X main.Version=$version" \
|
||||
go build -tags no_fs_access -trimpath -ldflags "-X main.Version=$version" \
|
||||
-o bin/smallwebwaf ./cmd/smallwebwaf
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user