Paths the request rate limits do not count (SWWAF_RATE_LIMIT_EXEMPT_PATHS) #77

Open
opened 2026-10-06 11:41:05 +02:00 by clawbot · 4 comments
Collaborator

SWWAF_RATE_LIMIT_EXEMPT_PATHS, as "Configuration surface" in SPEC.md describes it: path prefixes whose requests the request rate limits do not count (static assets, health checks). The build order in SPEC.md puts the exemptions in the first stage after milestone 2.

What it builds

  • SWWAF_RATE_LIMIT_EXEMPT_PATHS: a comma-separated list of path prefixes, empty by default. A request whose path starts with one is neither counted by the request rate limits nor refused by them; every other check still applies (the network lists, the ban ledger, the country lists). A prefix that does not start with / stops the start with a message naming the setting.
  • Matching is on the request's path as received, before any query string, by plain prefix; README.md says how a prefix such as /assets/ matches and what it does not (no wildcards).
  • The request log line and the metrics show such a request as forwarded, with no limit_hit.
  • README.md documents the setting.

Definition of done

  • Tests show an exempt path neither counted nor refused while the client is over a limit, a path outside every prefix still counted, a ban still refusing an exempt path, the default, and the start refused for an invalid prefix; each fails with its rule broken.
  • make check green; one PR to next, passed by a reviewer who did not write it.

Model: opus-5-5

`SWWAF_RATE_LIMIT_EXEMPT_PATHS`, as "Configuration surface" in `SPEC.md` describes it: path prefixes whose requests the request rate limits do not count (static assets, health checks). The build order in `SPEC.md` puts the exemptions in the first stage after milestone 2. ## What it builds - `SWWAF_RATE_LIMIT_EXEMPT_PATHS`: a comma-separated list of path prefixes, empty by default. A request whose path starts with one is neither counted by the request rate limits nor refused by them; every other check still applies (the network lists, the ban ledger, the country lists). A prefix that does not start with `/` stops the start with a message naming the setting. - Matching is on the request's path as received, before any query string, by plain prefix; `README.md` says how a prefix such as `/assets/` matches and what it does not (no wildcards). - The request log line and the metrics show such a request as forwarded, with no `limit_hit`. - `README.md` documents the setting. ## Definition of done - Tests show an exempt path neither counted nor refused while the client is over a limit, a path outside every prefix still counted, a ban still refusing an exempt path, the default, and the start refused for an invalid prefix; each fails with its rule broken. - `make check` green; one PR to `next`, passed by a reviewer who did not write it. Model: opus-5-5
clawbot self-assigned this 2026-10-06 11:41:05 +02:00
Author
Collaborator

Implemented in #80, for review.

Model: opus-5-5

Implemented in https://git.eeqj.de/sneak/smallwebwaf/pulls/80, for review. Model: opus-5-5
Author
Collaborator

Correction to the issue body, from the review of #80: matching the path as received lets a client escape the rate limits for a path outside the prefix (/assets/..%2Flogin reaches an app that resolves it as /login). A request is exempt only when the path the app will act on starts with a prefix: the percent-decoded path with its . and .. segments and repeated slashes resolved.

Model: opus-5-5

Correction to the issue body, from the review of https://git.eeqj.de/sneak/smallwebwaf/pulls/80: matching the path as received lets a client escape the rate limits for a path outside the prefix (`/assets/..%2Flogin` reaches an app that resolves it as `/login`). A request is exempt only when the path the app will act on starts with a prefix: the percent-decoded path with its `.` and `..` segments and repeated slashes resolved. Model: opus-5-5
Author
Collaborator

Second correction, from the second review of #80: resolving the decoded path still lets a client escape the rate limits through an app that keeps an encoded slash inside a path segment (..%2F across segments, /assets%2Fx). The rule is now: a request whose percent-decoded path contains .. anywhere, or whose path as sent holds an encoded slash (%2F, %2f) or a backslash, is never exempt; any other request is exempt when its path starts with a prefix.

Model: opus-5-5

Second correction, from the second review of https://git.eeqj.de/sneak/smallwebwaf/pulls/80: resolving the decoded path still lets a client escape the rate limits through an app that keeps an encoded slash inside a path segment (`..%2F` across segments, `/assets%2Fx`). The rule is now: a request whose percent-decoded path contains `..` anywhere, or whose path as sent holds an encoded slash (`%2F`, `%2f`) or a backslash, is never exempt; any other request is exempt when its path starts with a prefix. Model: opus-5-5
Author
Collaborator

Third correction, from the third review of #80: prefixes are compared with the path as sent (the path the app receives), not the decoded one, so an encoded character of the prefix (/%61ssets/x) cannot escape the limits through a router that matches the path as received. The checks stay: a request whose percent-decoded path contains .., or whose path as sent holds an encoded slash or a backslash, is never exempt.

Model: opus-5-5

Third correction, from the third review of https://git.eeqj.de/sneak/smallwebwaf/pulls/80: prefixes are compared with the path as sent (the path the app receives), not the decoded one, so an encoded character of the prefix (`/%61ssets/x`) cannot escape the limits through a router that matches the path as received. The checks stay: a request whose percent-decoded path contains `..`, or whose path as sent holds an encoded slash or a backslash, is never exempt. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/smallwebwaf#77