Commit Graph
10 Commits
Author SHA1 Message Date
sneak 621c78df42 SPEC: further gitea refusals collected in a follow-up issue (closes #6)
Risks now says that gitea requests the Core Rule Set may still refuse at the defaults, found by reading gitea's source, are gathered in #30 and checked against a running gitea in milestone 1, rather than added to the spec one by one.

Model: opus-5-5
2026-09-28 22:43:07 +00:00
sneak 7b48306203 SPEC: gitea cookies and Referer kept from false refusals (closes #6)
Seventh review of the spec update:

- The Core Rule Set now reads requests without the `gitea_flash` and
  `redirect_to` cookies. A refusal there kept a browser out of the
  whole site, and not only 930120, 932160 and 932260 refuse ordinary
  names in them: the Java, script, PowerShell and database-name rules
  do too. Risks names an app that reads either cookie.
- `Referer` is left out of 932340 and 944110, which refused every
  request made from the results of a one-word search such as `env`,
  and from OpenJDK's `java.base` pages that name `Runtime`.
- The search note covers text whose first word has a listed command
  right after a `/`.

Model: opus-5-5
2026-09-28 22:28:53 +00:00
sneak 22f32a46ab SPEC: gitea branch names with a command after a slash (closes #6)
Sixth review of the spec update: the gitea note on branch, tag and
file names now also covers names with a listed command right after a
`/`, such as `feat/docker-support`, which rule 932260 refuses in the
same query parameters. It also says what saving such a branch
protection rule looks like: gitea stores it, then returns to the
branch settings page with `rule_name` in its address, which gets the
sidecar's 403 answer.

Model: opus-5-5
2026-09-28 21:34:57 +00:00
sneak 8b3aba84b2 SPEC: parameter change for every app, gitea name refusals, v3 uploads (closes #6)
Fifth review of the spec update:

- The change that leaves gitea's path and branch parameters out of
  930120, 932160 and 932260 says it holds in front of every app, that
  commands and file URLs pass there too, and that no setting restores
  the rules; Risks names an app that uses one of them as a server file
  or in a shell.
- The gitea notes no longer claim that any branch or file name passes:
  they name `refSubUrl`, `name`, `tag`, `template` and `rule_name`,
  which keep the rules, and what each refusal looks like.
- `actions/upload-artifact@v3` is refused once or twice per upload and
  the step fails; only more than 30 refusals a minute ban the runner.

Model: opus-5-5
2026-09-28 21:04:34 +00:00
sneak 44a95a6396 SPEC: gitea path parameters, runners, uploads, GeoJS, tokens (closes #6)
Fourth review of the spec update:

- The Core Rule Set's lists of system files, shell paths and command
  names no longer check the query parameters and cookie in which gitea
  sends file paths, branch names and sign-in redirects; searches stay
  checked.
- The gitea notes name uploads cut off by the size and time limits,
  upload-artifact v3's refused Content-Range header, and runners that
  pass the day limit, with RATE_LIMIT_EXEMPT_NETS for them.
- GeoJS is asked about at most 200 addresses at once; an answer without
  country_code counts as unknown.
- A set token shorter than 32 characters, or a RULES_DIR that does not
  exist, stops the start.

Model: opus-5-5
2026-09-28 20:18:49 +00:00
sneak 4020ff83c6 SPEC and README: bodies unread by default, one listener, GeoJS by default (closes #6)
Address the third review of the spec update and sneak's two new rulings.
By default the Core Rule Set reads the URL, query string and headers but
no request body, since a code forge's bodies carry code it takes for
attacks; `WAF_BODY_LIMIT` switches body inspection on. `Content-Encoding`
is allowed only on unread bodies, and OAuth sign-in from local tools
passes. The default rule file bans common probes for secrets, version
control, backups and logs at the site root. The spec names the Core Rule
Set 4.25.0. One listener answers the sidecar's own endpoints under
`/_smallwebwaf/`, behind tokens. GeoJS is the default lookup source. Size
suffixes are powers of 1024.

Model: opus-5-5
2026-09-28 18:50:00 +00:00
sneak 2d15e7e746 SPEC and README: rule set changes, error bursts, admin bans, GeoJS answers (closes #6)
Address the second review of the spec update. The Core Rule Set allows
PUT, PATCH and DELETE and the headers git and curl send, inspects only
bodies it can read, leaves responses alone, and by default switches off
the rules that refuse a code forge's ordinary files, uploads and git
traffic. The error burst counts only the sidecar's own refusals. Bans an
admin made are never dropped. A limit ban resets the client's counters.
GeoJS answers move to their own `lookups.json`. The spec now says which
address is the client when every forwarded address is trusted, that the
exclusive country list refuses private addresses, which are never sent to
GeoJS, what `close` gives behind traefik, and Spamhaus's terms for DROP.

Model: opus-5-5
2026-09-23 14:36:32 +00:00
sneak 8fc7539f1a SPEC and README: review fixes, country lists, GeoJS lookups (closes #6)
Address the review of the spec update and fold in issues 8 and 11.
Default ban rules are anchored at the site root. `bans.json` is bounded
by `MAX_BANS` and rewritten only when a ban is made, lifted or made
permanent. `clients.json` keeps one client per line, holds at most 20000
clients and is written every 15 minutes. Anomaly counters and alert
state go to a new `alerts.json`, the AbuseIPDB count to
`reputation.json`. 401 no longer counts toward the error burst. New
settings: `DENIED_COUNTRIES`, `EXCLUSIVELY_ALLOWED_COUNTRIES`,
`LOOKUP_SOURCE` (the IPinfo file or GeoJS), `LOOKUP_TIMEOUT`,
`CLIENT_REQUEST_HEADER_MAX_BYTES` and `CLIENT_IDLE_TIMEOUT`.

Model: opus-5-5
2026-09-23 13:37:34 +00:00
sneak 43c63faa04 SPEC and README: owner rulings, issues 2 to 5, internet-ready defaults (closes #6)
Rewrite `SPEC.md` and `README.md` to the owner's rulings. The seven answers
to the spec's questions now stand where their topics live, and the questions
section is gone. Bans follow the owner's model: seven days for a clear sign of
attack and permanent on any further request, an hour for a broken limit,
tripled on a repeat within a day, permanent past seven days. The state files
hold all state, are watched, and take in an admin's edits while running. Every
ban carries notes, and each client's history survives a restart. Size and time
limits apply in both directions. Only `UPSTREAM_URL` is required: the Core Rule
Set refuses what it flags and every limit has a default.

Model: opus-5-5
2026-09-23 12:46:05 +00:00
sneak a0d2c21346 Add README, SPEC and tool evaluation, closes #1
Initial documents: what smallwebwaf is and why, the proposed feature list, the design spec with the rule file format and the open design questions, and the survey of existing tools.

Model: fable-5-1
2026-09-21 07:42:45 +00:00