Core Rule Set reads request bodies up to SWWAF_WAF_BODY_LIMIT (closes #116)
check / check (push) Waiting to run
check / check (push) Waiting to run
SWWAF_WAF_BODY_LIMIT (default off, at most 1G) has the Core Rule Set read form data and multipart up to the limit, the rest streaming on, and JSON and XML (with +json, text/json and +xml) no larger than it. The part read is held for the app. A size or time limit met while reading ends the request. Content-Encoding is refused again on these kinds. A body Coraza cannot parse, or a multipart body failing its strict checks, adds 5, but not a multipart body reaching the limit. Coraza is built with no_fs_access, so writes no file. Rule 900300 moves to phase 2. Judgement call: Content-Encoding is refused on a JSON or XML body too large to read, as SPEC.md allows. Model: opus-5-5
This commit is contained in:
@@ -21,6 +21,9 @@ type requestBody struct {
|
||||
// SWWAF_REQUEST_MAX_BYTES.
|
||||
body io.ReadCloser
|
||||
rq *request
|
||||
// readByCoreRuleSet is what the Core Rule Set read of the body before
|
||||
// the request went to the app, and Read gives first.
|
||||
readByCoreRuleSet []byte
|
||||
// waiting is true while a Read waits for the client to send more.
|
||||
waiting atomic.Bool
|
||||
// received is true once the client has sent the whole body.
|
||||
@@ -29,8 +32,16 @@ type requestBody struct {
|
||||
bytes atomic.Int64
|
||||
}
|
||||
|
||||
// Read reads from the client's body.
|
||||
// Read reads from the client's body, after what the Core Rule Set read of
|
||||
// it, which has been counted already.
|
||||
func (b *requestBody) Read(p []byte) (int, error) {
|
||||
if len(b.readByCoreRuleSet) > 0 {
|
||||
n := copy(p, b.readByCoreRuleSet)
|
||||
b.readByCoreRuleSet = b.readByCoreRuleSet[n:]
|
||||
|
||||
return n, nil
|
||||
}
|
||||
|
||||
b.waiting.Store(true)
|
||||
n, err := b.body.Read(p)
|
||||
b.waiting.Store(false)
|
||||
|
||||
Reference in New Issue
Block a user