Two parts of the last stage of the build order in SPEC.md that need no Core Rule Set: trap paths and the error burst. One PR to next.
SWWAF_TRAP_PATHS: paths the app never serves and only scanners ask for (for example /wp-login.php,/xmlrpc.php). A request for one is a clear sign of attack, banned as a ban rule's match is ("Bans"), with the trap path in the ban's notes; the env-var short form of a path rule with the ban action, matched as a path rule is. Malformed entries stop the start naming the setting.
SWWAF_ERROR_BURST_THRESHOLD (default 30): more than this many requests per client per minute that smallwebwaf refused after a rule file match (block or ban), or for a missing or wrong admin or metrics token, breaks a limit and bans the client by the rules for a broken limit; answers the app gave are not counted. Core Rule Set refusals join the count when #25 lands. off switches it off.
Each such refusal is an offence counted by kind in the client's history, where not already; the request log's limit_hit names the error burst; ban notes say what was counted; metrics as "Metrics endpoint" gives them; observe mode logs and alerts what would have happened.
README.md documents both.
Definition of done: tests, on a clock the test controls, show a trap path banning, the error burst breaking at one over the threshold from rule refusals and from token failures (each kind and a mix), answers the app gave not counted, off, the start errors, and the log, notes and metrics; each test failing with its rule broken; make check green; one PR to next, passed by a reviewer who did not write it.
Model: opus-5-5
Two parts of the last stage of the build order in `SPEC.md` that need no Core Rule Set: trap paths and the error burst. One PR to `next`.
- `SWWAF_TRAP_PATHS`: paths the app never serves and only scanners ask for (for example `/wp-login.php,/xmlrpc.php`). A request for one is a clear sign of attack, banned as a `ban` rule's match is ("Bans"), with the trap path in the ban's notes; the env-var short form of a `path` rule with the `ban` action, matched as a `path` rule is. Malformed entries stop the start naming the setting.
- `SWWAF_ERROR_BURST_THRESHOLD` (default `30`): more than this many requests per client per minute that `smallwebwaf` refused after a rule file match (`block` or `ban`), or for a missing or wrong admin or metrics token, breaks a limit and bans the client by the rules for a broken limit; answers the app gave are not counted. Core Rule Set refusals join the count when https://git.eeqj.de/sneak/smallwebwaf/issues/25 lands. `off` switches it off.
- Each such refusal is an offence counted by kind in the client's history, where not already; the request log's `limit_hit` names the error burst; ban notes say what was counted; metrics as "Metrics endpoint" gives them; `observe` mode logs and alerts what would have happened.
- `README.md` documents both.
Definition of done: tests, on a clock the test controls, show a trap path banning, the error burst breaking at one over the threshold from rule refusals and from token failures (each kind and a mix), answers the app gave not counted, `off`, the start errors, and the log, notes and metrics; each test failing with its rule broken; `make check` green; one PR to `next`, passed by a reviewer who did not write it.
Model: opus-5-5
clawbot
self-assigned this 2026-10-08 03:08:34 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Two parts of the last stage of the build order in
SPEC.mdthat need no Core Rule Set: trap paths and the error burst. One PR tonext.SWWAF_TRAP_PATHS: paths the app never serves and only scanners ask for (for example/wp-login.php,/xmlrpc.php). A request for one is a clear sign of attack, banned as abanrule's match is ("Bans"), with the trap path in the ban's notes; the env-var short form of apathrule with thebanaction, matched as apathrule is. Malformed entries stop the start naming the setting.SWWAF_ERROR_BURST_THRESHOLD(default30): more than this many requests per client per minute thatsmallwebwafrefused after a rule file match (blockorban), or for a missing or wrong admin or metrics token, breaks a limit and bans the client by the rules for a broken limit; answers the app gave are not counted. Core Rule Set refusals join the count when #25 lands.offswitches it off.limit_hitnames the error burst; ban notes say what was counted; metrics as "Metrics endpoint" gives them;observemode logs and alerts what would have happened.README.mddocuments both.Definition of done: tests, on a clock the test controls, show a trap path banning, the error burst breaking at one over the threshold from rule refusals and from token failures (each kind and a mix), answers the app gave not counted,
off, the start errors, and the log, notes and metrics; each test failing with its rule broken;make checkgreen; one PR tonext, passed by a reviewer who did not write it.Model: opus-5-5
Built in #118, waiting for review.
Model: opus-5-5