Core Rule Set reads request bodies up to SWWAF_WAF_BODY_LIMIT (closes #116)
check / check (push) Canceled after 0s
check / check (push) Canceled after 0s
SWWAF_WAF_BODY_LIMIT (default off) has the Core Rule Set read form data and multipart up to the limit, the rest streaming on, and JSON and XML no larger than it; other bodies pass uninspected. The part read is held and sent to the app ahead of the rest. The client has SWWAF_CLIENT_REQUEST_TIMEOUT to send it, and a size or time limit met while it is read ends the request before it reaches the app. Content-Encoding is refused again on those four kinds. Rule 900300 moves to phase 2, so it counts form and JSON fields past Coraza's 1000 too. Judgement call: Content-Encoding is refused on a JSON or XML body too large to be read, which SPEC.md allows. Model: opus-5-5
This commit is contained in:
@@ -244,14 +244,16 @@ type Config struct {
|
||||
// level, from 1 to 4 (SWWAF_WAF_PARANOIA_LEVEL), and
|
||||
// WAFAnomalyThreshold the anomaly score at which a request is a match
|
||||
// (SWWAF_WAF_ANOMALY_THRESHOLD), 0 while it is off. WAFDisabledRules
|
||||
// are the ids of its rules switched off (SWWAF_WAF_DISABLED_RULES), and
|
||||
// are the ids of its rules switched off (SWWAF_WAF_DISABLED_RULES),
|
||||
// WAFExemptPaths the path prefixes it does not inspect
|
||||
// (SWWAF_WAF_EXEMPT_PATHS).
|
||||
// (SWWAF_WAF_EXEMPT_PATHS), and WAFBodyLimit the most of a request body
|
||||
// it reads (SWWAF_WAF_BODY_LIMIT), 0 while it is off and it reads none.
|
||||
WAFMode string
|
||||
WAFParanoiaLevel int
|
||||
WAFAnomalyThreshold int
|
||||
WAFDisabledRules []int
|
||||
WAFExemptPaths []string
|
||||
WAFBodyLimit int64
|
||||
// TrapPaths are the paths a request for which is a clear sign of
|
||||
// attack (SWWAF_TRAP_PATHS), each starting with / and without a ?.
|
||||
TrapPaths []string
|
||||
@@ -559,6 +561,7 @@ func FromEnvironment(lookupEnv func(string) (string, bool)) (*Config, error) {
|
||||
WAFDisabledRules: env.ruleIDs("SWWAF_WAF_DISABLED_RULES",
|
||||
"920340,920420,920440,920640,930130,930140"),
|
||||
WAFExemptPaths: env.pathPrefixes("SWWAF_WAF_EXEMPT_PATHS", ""),
|
||||
WAFBodyLimit: env.size("SWWAF_WAF_BODY_LIMIT", off),
|
||||
TrapPaths: env.trapPaths("SWWAF_TRAP_PATHS"),
|
||||
ErrorBurstThreshold: env.count("SWWAF_ERROR_BURST_THRESHOLD", "30"),
|
||||
LogRemoteURL: env.logRemoteURL("SWWAF_LOG_REMOTE_URL"),
|
||||
|
||||
Reference in New Issue
Block a user