Trap paths, and the error burst banning a client refused too often (closes #115)
check / check (push) Waiting to run
check / check (push) Waiting to run
SWWAF_TRAP_PATHS: a request whose path, as a path rule sees it, is one of them is a clear sign of attack, banned as a ban rule's match is; the ban's notes give its trap_path. Checked after the rate limits, before the rule files. SWWAF_ERROR_BURST_THRESHOLD (default 30, or off): more refusals in a minute after a block or ban rule or a trap path, or for a missing or wrong token, ban the client as a broken limit does. Counted in clients.json's minute_refusals; limit_hit error_burst, notes kind refusals. A token refusal is now the offence token_refused, and smallwebwaf_offences_total counts every kind the history does. Judgement call: the threshold is not lowered by a client's limit percentage. Model: opus-5-5
This commit was merged in pull request #118.
This commit is contained in:
+13
-6
@@ -396,16 +396,23 @@ func (rule Rule) matches(r *http.Request) bool {
|
||||
return rule.regex.MatchString(value(rule.Target, r))
|
||||
}
|
||||
|
||||
// Path returns r's path as the client sent it, before any decoding or
|
||||
// re-encoding, up to the first ?: what a path rule is matched against.
|
||||
func Path(r *http.Request) string {
|
||||
path, _, _ := strings.Cut(pathAndQuery(r), "?")
|
||||
|
||||
return path
|
||||
}
|
||||
|
||||
// value returns what a rule with target, other than uri, is matched
|
||||
// against in r: the path and the query as the client sent them, before
|
||||
// any decoding or re-encoding, split at the first ?, and a header's values
|
||||
// joined by ", ", as HTTP joins those of a header sent more than once.
|
||||
// against in r: the path, as Path gives it, and the query as the client
|
||||
// sent it, before any decoding or re-encoding, after the first ?, and a
|
||||
// header's values joined by ", ", as HTTP joins those of a header sent
|
||||
// more than once.
|
||||
func value(target string, r *http.Request) string {
|
||||
switch target {
|
||||
case "path":
|
||||
path, _, _ := strings.Cut(pathAndQuery(r), "?")
|
||||
|
||||
return path
|
||||
return Path(r)
|
||||
case "query":
|
||||
_, query, _ := strings.Cut(pathAndQuery(r), "?")
|
||||
|
||||
|
||||
Reference in New Issue
Block a user