Leave SWWAF_RATE_LIMIT_EXEMPT_PATHS out of the request rate limits (closes #77)
check / check (push) Successful in 4m48s
check / check (push) Successful in 4m48s
A request whose path, as the client sent it and before the query string, starts with one of the comma-separated prefixes in SWWAF_RATE_LIMIT_EXEMPT_PATHS is neither counted nor refused by the request rate limits; the static lists, bans and the country lists still apply. The setting is empty by default, and a prefix that does not start with / stops the start. README.md documents it. Judgement call: plain prefix on the path as sent, as the issue rules, so /assets/../login matches /assets/; traefik removes such dot segments by default, but a request that reaches smallwebwaf uncleaned is matched as sent. Model: opus-5-5
This commit is contained in:
@@ -58,6 +58,7 @@ const (
|
||||
denyNets = "SWWAF_DENY_NETS"
|
||||
rateLimitPerMinute = "SWWAF_RATE_LIMIT_PER_MINUTE"
|
||||
rateLimitPerDay = "SWWAF_RATE_LIMIT_PER_DAY"
|
||||
rateLimitExemptPaths = "SWWAF_RATE_LIMIT_EXEMPT_PATHS"
|
||||
deniedCountries = "SWWAF_DENIED_COUNTRIES"
|
||||
allowedCountries = "SWWAF_EXCLUSIVELY_ALLOWED_COUNTRIES"
|
||||
banResponse = "SWWAF_BAN_RESPONSE"
|
||||
|
||||
Reference in New Issue
Block a user