Compare commits

..
1 Commits
Author SHA1 Message Date
clawbot 928ad4a11c Core Rule Set reads request bodies up to SWWAF_WAF_BODY_LIMIT (closes #116)
check / check (push) Waiting to run
SWWAF_WAF_BODY_LIMIT (default off, at most 1G) has the Core Rule Set read
form data and multipart up to the limit, the rest streaming on, and JSON
and XML (with +json, text/json and +xml) no larger than it. The part read
is held for the app. A size or time limit met while reading ends the
request. Content-Encoding is refused again on these kinds. A body Coraza
cannot parse, or a multipart body failing its strict checks, adds 5, but
not a multipart body reaching the limit. Coraza is built with
no_fs_access, so writes no file. Rule 900300 moves to phase 2.

Judgement call: Content-Encoding is refused on a JSON or XML body too
large to read, as SPEC.md allows.

Model: opus-5-5
2026-10-08 09:07:26 +00:00
+1 -1
View File
@@ -718,7 +718,7 @@ effective settings are logged at start, unless `SWWAF_LOG_LEVEL` is `warn` or
`+json`, or is `text/json`, is JSON, and one whose type ends in `+xml` is XML.
Any other body reaches the app uninspected, and so does a larger JSON or XML
body: the Core Rule Set would read any other body as form data, where binary
content such as a git push trips rules written for text. A body it reads that
content such as a git push trips rules written for text. A body read that
Coraza cannot parse (rule 900440), and a multipart body that fails Coraza's
strict checks (rule 900450), add 5 to the score, as a rule rated critical
does, since no rule reads what comes after the fault; a multipart body that