EXCLUSIVELY_ALLOWED_COUNTRIES="us,de" # blocks all geoip countries except these
DENIED_COUNTRIES="cn,ru,nk,ir,ua,by" # immediate deny based on source country
eg:
`EXCLUSIVELY_ALLOWED_COUNTRIES="us,de" # blocks all geoip countries except these`
`DENIED_COUNTRIES="cn,ru,nk,ir,ua,by" # immediate deny based on source country`
when a request is blocked by one of these, no waf or ruleset matching is required. put it in metrics and move on. this can happen even before reading the request body, as soon as we see the client IP. i'd say just drop the connections but traefik will give 5xx then i assume, so respond with a 403 or 429 or whatever we're using to deny banned hosts.
when a request is blocked by one of these, no waf or ruleset matching is required. put it in metrics and move on. this can happen even before reading the request body, as soon as we see the client IP. i'd say just drop the connections but traefik will give 5xx then i assume, so respond with a 403 or 429 or whatever we're using to deny banned hosts.
Folded into the spec update, #9, which will close this issue. The spec adds EXCLUSIVELY_ALLOWED_COUNTRIES and DENIED_COUNTRIES as you wrote them: a request from a denied country, or, when the exclusive list is set, from any country not on it, is refused as soon as the client address is known, before the body is read. It skips the rule files and the Core Rule Set, is counted in the metrics, and gets the same answer as a banned client (BAN_RESPONSE, 403 by default). Both lists need the lookup database, so setting either without it stops the start. North Korea's code is kp; nk is not a country code, and an unknown code stops the start with a message naming it rather than blocking nothing.
Model: opus-5-5
Folded into the spec update, https://git.eeqj.de/sneak/smallwebwaf/pulls/9, which will close this issue. The spec adds `EXCLUSIVELY_ALLOWED_COUNTRIES` and `DENIED_COUNTRIES` as you wrote them: a request from a denied country, or, when the exclusive list is set, from any country not on it, is refused as soon as the client address is known, before the body is read. It skips the rule files and the Core Rule Set, is counted in the metrics, and gets the same answer as a banned client (`BAN_RESPONSE`, 403 by default). Both lists need the lookup database, so setting either without it stops the start. North Korea's code is `kp`; `nk` is not a country code, and an unknown code stops the start with a message naming it rather than blocking nothing.
Model: opus-5-5
clawbot
self-assigned this 2026-09-23 15:00:18 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
eg:
EXCLUSIVELY_ALLOWED_COUNTRIES="us,de" # blocks all geoip countries except theseDENIED_COUNTRIES="cn,ru,nk,ir,ua,by" # immediate deny based on source countrywhen a request is blocked by one of these, no waf or ruleset matching is required. put it in metrics and move on. this can happen even before reading the request body, as soon as we see the client IP. i'd say just drop the connections but traefik will give 5xx then i assume, so respond with a 403 or 429 or whatever we're using to deny banned hosts.
Folded into the spec update, #9, which will close this issue. The spec adds
EXCLUSIVELY_ALLOWED_COUNTRIESandDENIED_COUNTRIESas you wrote them: a request from a denied country, or, when the exclusive list is set, from any country not on it, is refused as soon as the client address is known, before the body is read. It skips the rule files and the Core Rule Set, is counted in the metrics, and gets the same answer as a banned client (BAN_RESPONSE, 403 by default). Both lists need the lookup database, so setting either without it stops the start. North Korea's code iskp;nkis not a country code, and an unknown code stops the start with a message naming it rather than blocking nothing.Model: opus-5-5
Closed by the merge of #9 into
next(commit7898957).Model: opus-5-5