Observe mode: log what would be refused, refuse nothing #78

Closed
opened 2026-10-06 11:41:05 +02:00 by clawbot · 1 comment
Collaborator

SWWAF_MODE=observe, as SPEC.md describes it ("Configuration surface", the request log's would_action, "Admin endpoints"): smallwebwaf logs every decision as what would have happened and refuses nothing. The build order in SPEC.md puts observe mode in the first stage after milestone 2.

What it builds

  • SWWAF_MODE (default enforce): enforce or observe; any other value stops the start naming the setting.
  • In observe mode every refusal that exists by then (a broken rate limit, the ban ledger, the country lists, SWWAF_DENY_NETS) forwards the request instead, and its log line gets would_action with the action enforce mode would have taken; action is forward. Counting, history and metrics go on as in enforce mode. No ban is made in observe mode (a broken limit is logged as would_action rate_limited); bans already in bans.json are not enforced but kept.
  • The size and time limits still apply in observe mode, since they protect smallwebwaf and the app themselves; the PR says so in README.md. A missing or wrong token at /_smallwebwaf/ is still answered 401, as "Admin endpoints" says.
  • The start logs the mode, and README.md documents it, including that observe is for trying a configuration before enforcing it.

Definition of done

  • Tests show, for each refusal, the request forwarded with the right would_action in observe mode and refused in enforce mode; no ban made in observe mode; the size limits and the 401 still applying; the default and an invalid value.
  • make check green; one PR to next, passed by a reviewer who did not write it.

Model: opus-5-5

`SWWAF_MODE=observe`, as `SPEC.md` describes it ("Configuration surface", the request log's `would_action`, "Admin endpoints"): `smallwebwaf` logs every decision as what would have happened and refuses nothing. The build order in `SPEC.md` puts `observe` mode in the first stage after milestone 2. ## What it builds - `SWWAF_MODE` (default `enforce`): `enforce` or `observe`; any other value stops the start naming the setting. - In `observe` mode every refusal that exists by then (a broken rate limit, the ban ledger, the country lists, `SWWAF_DENY_NETS`) forwards the request instead, and its log line gets `would_action` with the action enforce mode would have taken; `action` is `forward`. Counting, history and metrics go on as in enforce mode. No ban is made in `observe` mode (a broken limit is logged as `would_action` `rate_limited`); bans already in `bans.json` are not enforced but kept. - The size and time limits still apply in `observe` mode, since they protect `smallwebwaf` and the app themselves; the PR says so in `README.md`. A missing or wrong token at `/_smallwebwaf/` is still answered `401`, as "Admin endpoints" says. - The start logs the mode, and `README.md` documents it, including that `observe` is for trying a configuration before enforcing it. ## Definition of done - Tests show, for each refusal, the request forwarded with the right `would_action` in `observe` mode and refused in `enforce` mode; no ban made in `observe` mode; the size limits and the `401` still applying; the default and an invalid value. - `make check` green; one PR to `next`, passed by a reviewer who did not write it. Model: opus-5-5
clawbot self-assigned this 2026-10-06 11:41:05 +02:00
Author
Collaborator

Implemented in #81.

Model: opus-5-5

Implemented in https://git.eeqj.de/sneak/smallwebwaf/pulls/81. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/smallwebwaf#78