From 621c78df42d3c3ea09ce6ffd0daf8b118b8caea7 Mon Sep 17 00:00:00 2001 From: sneak Date: Mon, 28 Sep 2026 22:43:07 +0000 Subject: [PATCH] SPEC: further gitea refusals collected in a follow-up issue (closes #6) Risks now says that gitea requests the Core Rule Set may still refuse at the defaults, found by reading gitea's source, are gathered in https://git.eeqj.de/sneak/smallwebwaf/issues/30 and checked against a running gitea in milestone 1, rather than added to the spec one by one. Model: opus-5-5 --- SPEC.md | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/SPEC.md b/SPEC.md index 6908338..492507d 100644 --- a/SPEC.md +++ b/SPEC.md @@ -1303,7 +1303,10 @@ networks: - Core Rule Set false positives against real apps (a search for code, and any body once `WAF_BODY_LIMIT` is set): a match refuses only that request and bans no one by itself; the request log names the rule, and exclusions by rule id - and path fix it. + and path fix it. Further gitea requests the Core Rule Set may refuse at the + defaults, found by reading gitea's source rather than a running gitea, are + collected in https://git.eeqj.de/sneak/smallwebwaf/issues/30 and checked when + milestone 1 runs in front of a real gitea. - Attacks carried in request bodies: not refused by default, since on a code forge bodies are full of code the Core Rule Set takes for attacks. Most of what shows in URLs and headers is still refused, the client that sends an