Trap paths and the error burst #115

Open
opened 2026-10-08 03:08:34 +02:00 by clawbot · 1 comment
Collaborator

Two parts of the last stage of the build order in SPEC.md that need no Core Rule Set: trap paths and the error burst. One PR to next.

  • SWWAF_TRAP_PATHS: paths the app never serves and only scanners ask for (for example /wp-login.php,/xmlrpc.php). A request for one is a clear sign of attack, banned as a ban rule's match is ("Bans"), with the trap path in the ban's notes; the env-var short form of a path rule with the ban action, matched as a path rule is. Malformed entries stop the start naming the setting.
  • SWWAF_ERROR_BURST_THRESHOLD (default 30): more than this many requests per client per minute that smallwebwaf refused after a rule file match (block or ban), or for a missing or wrong admin or metrics token, breaks a limit and bans the client by the rules for a broken limit; answers the app gave are not counted. Core Rule Set refusals join the count when #25 lands. off switches it off.
  • Each such refusal is an offence counted by kind in the client's history, where not already; the request log's limit_hit names the error burst; ban notes say what was counted; metrics as "Metrics endpoint" gives them; observe mode logs and alerts what would have happened.
  • README.md documents both.

Definition of done: tests, on a clock the test controls, show a trap path banning, the error burst breaking at one over the threshold from rule refusals and from token failures (each kind and a mix), answers the app gave not counted, off, the start errors, and the log, notes and metrics; each test failing with its rule broken; make check green; one PR to next, passed by a reviewer who did not write it.

Model: opus-5-5

Two parts of the last stage of the build order in `SPEC.md` that need no Core Rule Set: trap paths and the error burst. One PR to `next`. - `SWWAF_TRAP_PATHS`: paths the app never serves and only scanners ask for (for example `/wp-login.php,/xmlrpc.php`). A request for one is a clear sign of attack, banned as a `ban` rule's match is ("Bans"), with the trap path in the ban's notes; the env-var short form of a `path` rule with the `ban` action, matched as a `path` rule is. Malformed entries stop the start naming the setting. - `SWWAF_ERROR_BURST_THRESHOLD` (default `30`): more than this many requests per client per minute that `smallwebwaf` refused after a rule file match (`block` or `ban`), or for a missing or wrong admin or metrics token, breaks a limit and bans the client by the rules for a broken limit; answers the app gave are not counted. Core Rule Set refusals join the count when https://git.eeqj.de/sneak/smallwebwaf/issues/25 lands. `off` switches it off. - Each such refusal is an offence counted by kind in the client's history, where not already; the request log's `limit_hit` names the error burst; ban notes say what was counted; metrics as "Metrics endpoint" gives them; `observe` mode logs and alerts what would have happened. - `README.md` documents both. Definition of done: tests, on a clock the test controls, show a trap path banning, the error burst breaking at one over the threshold from rule refusals and from token failures (each kind and a mix), answers the app gave not counted, `off`, the start errors, and the log, notes and metrics; each test failing with its rule broken; `make check` green; one PR to `next`, passed by a reviewer who did not write it. Model: opus-5-5
clawbot self-assigned this 2026-10-08 03:08:34 +02:00
Author
Collaborator

Built in #118, waiting for review.

Model: opus-5-5

Built in https://git.eeqj.de/sneak/smallwebwaf/pulls/118, waiting for review. Model: opus-5-5
Sign in to join this conversation.