Body inspection by the Core Rule Set (SWWAF_WAF_BODY_LIMIT) #116

Open
opened 2026-10-08 03:38:47 +02:00 by clawbot · 1 comment
Collaborator

Body inspection by the Core Rule Set, SWWAF_WAF_BODY_LIMIT, as "Attack detection" and "Data flow for one request" in SPEC.md give it. Built after the Core Rule Set itself (#25). One PR to next.

  • SWWAF_WAF_BODY_LIMIT (default off): a size, such as 128K, has the Core Rule Set read form data and multipart bodies up to that size, streaming the rest of a longer one on without holding it in memory, and JSON and XML bodies no larger than it; any other body, and a larger JSON or XML body, reaches the app uninspected.
  • Content-Encoding on a body that is read stays refused, as the six changes say.
  • README.md documents it, with the gitea cases SPEC.md names as refused once bodies are read.

Definition of done: tests show form, multipart, JSON and XML bodies inspected within the limit, a longer form body streamed past the limit without being held in memory, a larger JSON body and a binary body passed uninspected, an attack in a read body refused, and off; each test failing with its rule broken; make check green; one PR to next, passed by a reviewer who did not write it.

Model: opus-5-5

Body inspection by the Core Rule Set, `SWWAF_WAF_BODY_LIMIT`, as "Attack detection" and "Data flow for one request" in `SPEC.md` give it. Built after the Core Rule Set itself (https://git.eeqj.de/sneak/smallwebwaf/issues/25). One PR to `next`. - `SWWAF_WAF_BODY_LIMIT` (default `off`): a size, such as `128K`, has the Core Rule Set read form data and multipart bodies up to that size, streaming the rest of a longer one on without holding it in memory, and JSON and XML bodies no larger than it; any other body, and a larger JSON or XML body, reaches the app uninspected. - `Content-Encoding` on a body that is read stays refused, as the six changes say. - `README.md` documents it, with the gitea cases `SPEC.md` names as refused once bodies are read. Definition of done: tests show form, multipart, JSON and XML bodies inspected within the limit, a longer form body streamed past the limit without being held in memory, a larger JSON body and a binary body passed uninspected, an attack in a read body refused, and `off`; each test failing with its rule broken; `make check` green; one PR to `next`, passed by a reviewer who did not write it. Model: opus-5-5
clawbot self-assigned this 2026-10-08 03:38:47 +02:00
Author
Collaborator

PR: #122

Model: opus-5-5

PR: https://git.eeqj.de/sneak/smallwebwaf/pulls/122 Model: opus-5-5
Sign in to join this conversation.