SWWAF_RATE_LIMIT_EXEMPT_PATHS, as "Configuration surface" in SPEC.md describes it: path prefixes whose requests the request rate limits do not count (static assets, health checks). The build order in SPEC.md puts the exemptions in the first stage after milestone 2.
What it builds
SWWAF_RATE_LIMIT_EXEMPT_PATHS: a comma-separated list of path prefixes, empty by default. A request whose path starts with one is neither counted by the request rate limits nor refused by them; every other check still applies (the network lists, the ban ledger, the country lists). A prefix that does not start with / stops the start with a message naming the setting.
Matching is on the request's path as received, before any query string, by plain prefix; README.md says how a prefix such as /assets/ matches and what it does not (no wildcards).
The request log line and the metrics show such a request as forwarded, with no limit_hit.
README.md documents the setting.
Definition of done
Tests show an exempt path neither counted nor refused while the client is over a limit, a path outside every prefix still counted, a ban still refusing an exempt path, the default, and the start refused for an invalid prefix; each fails with its rule broken.
make check green; one PR to next, passed by a reviewer who did not write it.
Model: opus-5-5
`SWWAF_RATE_LIMIT_EXEMPT_PATHS`, as "Configuration surface" in `SPEC.md` describes it: path prefixes whose requests the request rate limits do not count (static assets, health checks). The build order in `SPEC.md` puts the exemptions in the first stage after milestone 2.
## What it builds
- `SWWAF_RATE_LIMIT_EXEMPT_PATHS`: a comma-separated list of path prefixes, empty by default. A request whose path starts with one is neither counted by the request rate limits nor refused by them; every other check still applies (the network lists, the ban ledger, the country lists). A prefix that does not start with `/` stops the start with a message naming the setting.
- Matching is on the request's path as received, before any query string, by plain prefix; `README.md` says how a prefix such as `/assets/` matches and what it does not (no wildcards).
- The request log line and the metrics show such a request as forwarded, with no `limit_hit`.
- `README.md` documents the setting.
## Definition of done
- Tests show an exempt path neither counted nor refused while the client is over a limit, a path outside every prefix still counted, a ban still refusing an exempt path, the default, and the start refused for an invalid prefix; each fails with its rule broken.
- `make check` green; one PR to `next`, passed by a reviewer who did not write it.
Model: opus-5-5
clawbot
self-assigned this 2026-10-06 11:41:05 +02:00
Correction to the issue body, from the review of #80: matching the path as received lets a client escape the rate limits for a path outside the prefix (/assets/..%2Flogin reaches an app that resolves it as /login). A request is exempt only when the path the app will act on starts with a prefix: the percent-decoded path with its . and .. segments and repeated slashes resolved.
Model: opus-5-5
Correction to the issue body, from the review of https://git.eeqj.de/sneak/smallwebwaf/pulls/80: matching the path as received lets a client escape the rate limits for a path outside the prefix (`/assets/..%2Flogin` reaches an app that resolves it as `/login`). A request is exempt only when the path the app will act on starts with a prefix: the percent-decoded path with its `.` and `..` segments and repeated slashes resolved.
Model: opus-5-5
Second correction, from the second review of #80: resolving the decoded path still lets a client escape the rate limits through an app that keeps an encoded slash inside a path segment (..%2F across segments, /assets%2Fx). The rule is now: a request whose percent-decoded path contains .. anywhere, or whose path as sent holds an encoded slash (%2F, %2f) or a backslash, is never exempt; any other request is exempt when its path starts with a prefix.
Model: opus-5-5
Second correction, from the second review of https://git.eeqj.de/sneak/smallwebwaf/pulls/80: resolving the decoded path still lets a client escape the rate limits through an app that keeps an encoded slash inside a path segment (`..%2F` across segments, `/assets%2Fx`). The rule is now: a request whose percent-decoded path contains `..` anywhere, or whose path as sent holds an encoded slash (`%2F`, `%2f`) or a backslash, is never exempt; any other request is exempt when its path starts with a prefix.
Model: opus-5-5
Third correction, from the third review of #80: prefixes are compared with the path as sent (the path the app receives), not the decoded one, so an encoded character of the prefix (/%61ssets/x) cannot escape the limits through a router that matches the path as received. The checks stay: a request whose percent-decoded path contains .., or whose path as sent holds an encoded slash or a backslash, is never exempt.
Model: opus-5-5
Third correction, from the third review of https://git.eeqj.de/sneak/smallwebwaf/pulls/80: prefixes are compared with the path as sent (the path the app receives), not the decoded one, so an encoded character of the prefix (`/%61ssets/x`) cannot escape the limits through a router that matches the path as received. The checks stay: a request whose percent-decoded path contains `..`, or whose path as sent holds an encoded slash or a backslash, is never exempt.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
SWWAF_RATE_LIMIT_EXEMPT_PATHS, as "Configuration surface" inSPEC.mddescribes it: path prefixes whose requests the request rate limits do not count (static assets, health checks). The build order inSPEC.mdputs the exemptions in the first stage after milestone 2.What it builds
SWWAF_RATE_LIMIT_EXEMPT_PATHS: a comma-separated list of path prefixes, empty by default. A request whose path starts with one is neither counted by the request rate limits nor refused by them; every other check still applies (the network lists, the ban ledger, the country lists). A prefix that does not start with/stops the start with a message naming the setting.README.mdsays how a prefix such as/assets/matches and what it does not (no wildcards).limit_hit.README.mddocuments the setting.Definition of done
make checkgreen; one PR tonext, passed by a reviewer who did not write it.Model: opus-5-5
Implemented in #80, for review.
Model: opus-5-5
Correction to the issue body, from the review of #80: matching the path as received lets a client escape the rate limits for a path outside the prefix (
/assets/..%2Floginreaches an app that resolves it as/login). A request is exempt only when the path the app will act on starts with a prefix: the percent-decoded path with its.and..segments and repeated slashes resolved.Model: opus-5-5
Second correction, from the second review of #80: resolving the decoded path still lets a client escape the rate limits through an app that keeps an encoded slash inside a path segment (
..%2Facross segments,/assets%2Fx). The rule is now: a request whose percent-decoded path contains..anywhere, or whose path as sent holds an encoded slash (%2F,%2f) or a backslash, is never exempt; any other request is exempt when its path starts with a prefix.Model: opus-5-5
Third correction, from the third review of #80: prefixes are compared with the path as sent (the path the app receives), not the decoded one, so an encoded character of the prefix (
/%61ssets/x) cannot escape the limits through a router that matches the path as received. The checks stay: a request whose percent-decoded path contains.., or whose path as sent holds an encoded slash or a backslash, is never exempt.Model: opus-5-5