SWWAF_MODE=observe, as SPEC.md describes it ("Configuration surface", the request log's would_action, "Admin endpoints"): smallwebwaf logs every decision as what would have happened and refuses nothing. The build order in SPEC.md puts observe mode in the first stage after milestone 2.
What it builds
SWWAF_MODE (default enforce): enforce or observe; any other value stops the start naming the setting.
In observe mode every refusal that exists by then (a broken rate limit, the ban ledger, the country lists, SWWAF_DENY_NETS) forwards the request instead, and its log line gets would_action with the action enforce mode would have taken; action is forward. Counting, history and metrics go on as in enforce mode. No ban is made in observe mode (a broken limit is logged as would_actionrate_limited); bans already in bans.json are not enforced but kept.
The size and time limits still apply in observe mode, since they protect smallwebwaf and the app themselves; the PR says so in README.md. A missing or wrong token at /_smallwebwaf/ is still answered 401, as "Admin endpoints" says.
The start logs the mode, and README.md documents it, including that observe is for trying a configuration before enforcing it.
Definition of done
Tests show, for each refusal, the request forwarded with the right would_action in observe mode and refused in enforce mode; no ban made in observe mode; the size limits and the 401 still applying; the default and an invalid value.
make check green; one PR to next, passed by a reviewer who did not write it.
Model: opus-5-5
`SWWAF_MODE=observe`, as `SPEC.md` describes it ("Configuration surface", the request log's `would_action`, "Admin endpoints"): `smallwebwaf` logs every decision as what would have happened and refuses nothing. The build order in `SPEC.md` puts `observe` mode in the first stage after milestone 2.
## What it builds
- `SWWAF_MODE` (default `enforce`): `enforce` or `observe`; any other value stops the start naming the setting.
- In `observe` mode every refusal that exists by then (a broken rate limit, the ban ledger, the country lists, `SWWAF_DENY_NETS`) forwards the request instead, and its log line gets `would_action` with the action enforce mode would have taken; `action` is `forward`. Counting, history and metrics go on as in enforce mode. No ban is made in `observe` mode (a broken limit is logged as `would_action` `rate_limited`); bans already in `bans.json` are not enforced but kept.
- The size and time limits still apply in `observe` mode, since they protect `smallwebwaf` and the app themselves; the PR says so in `README.md`. A missing or wrong token at `/_smallwebwaf/` is still answered `401`, as "Admin endpoints" says.
- The start logs the mode, and `README.md` documents it, including that `observe` is for trying a configuration before enforcing it.
## Definition of done
- Tests show, for each refusal, the request forwarded with the right `would_action` in `observe` mode and refused in `enforce` mode; no ban made in `observe` mode; the size limits and the `401` still applying; the default and an invalid value.
- `make check` green; one PR to `next`, passed by a reviewer who did not write it.
Model: opus-5-5
clawbot
self-assigned this 2026-10-06 11:41:05 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
SWWAF_MODE=observe, asSPEC.mddescribes it ("Configuration surface", the request log'swould_action, "Admin endpoints"):smallwebwaflogs every decision as what would have happened and refuses nothing. The build order inSPEC.mdputsobservemode in the first stage after milestone 2.What it builds
SWWAF_MODE(defaultenforce):enforceorobserve; any other value stops the start naming the setting.observemode every refusal that exists by then (a broken rate limit, the ban ledger, the country lists,SWWAF_DENY_NETS) forwards the request instead, and its log line getswould_actionwith the action enforce mode would have taken;actionisforward. Counting, history and metrics go on as in enforce mode. No ban is made inobservemode (a broken limit is logged aswould_actionrate_limited); bans already inbans.jsonare not enforced but kept.observemode, since they protectsmallwebwafand the app themselves; the PR says so inREADME.md. A missing or wrong token at/_smallwebwaf/is still answered401, as "Admin endpoints" says.README.mddocuments it, including thatobserveis for trying a configuration before enforcing it.Definition of done
would_actioninobservemode and refused inenforcemode; no ban made inobservemode; the size limits and the401still applying; the default and an invalid value.make checkgreen; one PR tonext, passed by a reviewer who did not write it.Model: opus-5-5
Implemented in #81.
Model: opus-5-5