SPEC.md "Rule files" defines the path target as the URL path as received, before any decoding, and every probe rule in the default file (and in the 50-gitea.rules example) uses path. So a client sending /%2eenv is not matched by env-file, while an app that decodes the path, as Go's server does, serves /.env. Found in review of #83, which builds the spec as written.
Options:
path is matched both as received and once percent-decoded, as uri already is. No new target; a rule written for the sent form still matches it.
The default file's probe rules use uri instead of path. uri holds the query too, so each regex ending in $ must also allow a query after the path.
Leave it; the Core Rule Set, a later stage, catches some encoded probes.
Recommendation: 1. Whichever you pick lands as its own change after #83; nothing waits on it.
Model: opus-5-5
`SPEC.md` "Rule files" defines the `path` target as the URL path as received, before any decoding, and every probe rule in the default file (and in the `50-gitea.rules` example) uses `path`. So a client sending `/%2eenv` is not matched by `env-file`, while an app that decodes the path, as Go's server does, serves `/.env`. Found in review of https://git.eeqj.de/sneak/smallwebwaf/pulls/83, which builds the spec as written.
Options:
1. `path` is matched both as received and once percent-decoded, as `uri` already is. No new target; a rule written for the sent form still matches it.
2. The default file's probe rules use `uri` instead of `path`. `uri` holds the query too, so each regex ending in `$` must also allow a query after the path.
3. Leave it; the Core Rule Set, a later stage, catches some encoded probes.
Recommendation: 1. Whichever you pick lands as its own change after https://git.eeqj.de/sneak/smallwebwaf/pulls/83; nothing waits on it.
Model: opus-5-5
sneak
was assigned by clawbot2026-10-06 18:16:27 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
SPEC.md"Rule files" defines thepathtarget as the URL path as received, before any decoding, and every probe rule in the default file (and in the50-gitea.rulesexample) usespath. So a client sending/%2eenvis not matched byenv-file, while an app that decodes the path, as Go's server does, serves/.env. Found in review of #83, which builds the spec as written.Options:
pathis matched both as received and once percent-decoded, asurialready is. No new target; a rule written for the sent form still matches it.uriinstead ofpath.uriholds the query too, so each regex ending in$must also allow a query after the path.Recommendation: 1. Whichever you pick lands as its own change after #83; nothing waits on it.
Model: opus-5-5