Core Rule Set reads request bodies up to SWWAF_WAF_BODY_LIMIT (closes #116)
check / check (push) Canceled after 0s
check / check (push) Canceled after 0s
SWWAF_WAF_BODY_LIMIT (default off) has the Core Rule Set read form data and multipart up to the limit, the rest streaming on, and JSON and XML no larger than it; other bodies pass uninspected. The part read is held and sent to the app first. A size or time limit met while it is read ends the request before it reaches the app. Content-Encoding is refused again on those four kinds. Rule 900300 moves to phase 2, to count form and JSON fields past Coraza's 1000 too. Judgement call: Content-Encoding is refused on a JSON or XML body too large to be read, which SPEC.md allows. Model: opus-5-5
This commit is contained in:
@@ -188,16 +188,23 @@ func requestHeaders(r *http.Request, names []string) map[string]string {
|
||||
}
|
||||
|
||||
// check is the one place where a request can be refused once its client
|
||||
// is known, before its body is read or anything reaches the app. It
|
||||
// returns nil to let the request through. The checks of checkClient come
|
||||
// first, answered with SWWAF_BAN_RESPONSE, or 403 for a block rule or the
|
||||
// Core Rule Set, and then the size limit, so that a request the rate
|
||||
// limits count is counted even when it is refused for its size. In
|
||||
// observe mode a request checkClient refuses goes on to the size limit
|
||||
// like any other. ctx is the request's own context.
|
||||
// is known, before anything reaches the app, and before its body is read,
|
||||
// but for the part the Core Rule Set reads. It returns nil to let the
|
||||
// request through. The checks of checkClient come first, answered with
|
||||
// SWWAF_BAN_RESPONSE, or 403 for a block rule or the Core Rule Set, and
|
||||
// then the size limit, so that a request the rate limits count is counted
|
||||
// even when it is refused for its size. In observe mode a request
|
||||
// checkClient refuses goes on to the size limit like any other. A size or
|
||||
// time limit the Core Rule Set's reading of the body meets ends the
|
||||
// request in either mode. ctx is the request's own context.
|
||||
func (rq *request) check(ctx context.Context) *refusal {
|
||||
action := rq.checkClient(ctx)
|
||||
|
||||
refused := rq.refused.Load()
|
||||
if refused != nil {
|
||||
return refused
|
||||
}
|
||||
|
||||
switch {
|
||||
case action == "":
|
||||
case rq.h.config.Observe:
|
||||
|
||||
Reference in New Issue
Block a user