SWWAF_WAF_BODY_LIMIT (default off) has the Core Rule Set read form data
and multipart up to the limit, the rest streaming on, and JSON and XML
no larger than it; other bodies pass uninspected. The part read is held
and sent to the app first. A size or time limit met while it is read
ends the request before it reaches the app. Content-Encoding is refused
again on those four kinds. Rule 900300 moves to phase 2, to count form
and JSON fields past Coraza's 1000 too.
Judgement call: Content-Encoding is refused on a JSON or XML body too
large to be read, which SPEC.md allows.
Model: opus-5-5
Coraza v3.8.1 runs the Core Rule Set 4.25.0 (coraza-coreruleset v4.25.0)
after the rule files, with the six changes and the default
SWWAF_WAF_DISABLED_RULES that SPEC.md gives; no body, no response. The
parameter names in the third and fourth changes are matched in any case,
as Coraza does. SWWAF_WAF_DISABLED_RULES refuses 900000 to 900999,
smallwebwaf's own rules. A request with more than 1000 query parameters
adds 5 (rule 900300). In block mode a match is refused with 403, an
offence counted toward the error burst; in detect mode it is let
through. Both log waf_rule_ids, waf_score and duration_waf, raise
waf_block, and count smallwebwaf_waf_matches_total.
Judgement call: waf_block is raised in block mode too.
Deviation: no engine-error path; with no body read, Coraza cannot fail.
Model: opus-5-5