Trap paths, and the error burst banning a client refused too often #118

Merged
clawbot merged 1 commits from issue-115-trap-paths-error-burst into next 2026-10-08 06:44:56 +02:00
Collaborator

Implements #115.

  • SWWAF_TRAP_PATHS: a request whose path, as a path rule sees it, is exactly one of them is banned as a ban rule's match is, with trap_path in the notes. Checked after the rate limits and before the rule files, which it does not need. An entry not starting with /, or holding a ?, stops the start.
  • SWWAF_ERROR_BURST_THRESHOLD (default 30, or off): each request refused after a block or ban rule or a trap path, or with 401 for a missing or wrong token, is counted per client over a minute (minute_refusals in clients.json); one over the threshold bans as a broken limit does, with limit_hit error_burst and notes kind refusals. The app's answers and SWWAF_ALLOW_NETS clients are not counted.
  • A token refusal is the new offence token_refused; smallwebwaf_offences_total now counts every kind the history counts, not only limit.
  • observe mode counts what enforce mode would have refused, and raises the ban alert it would have.

Disclosures:

  • Judgement call: a client's limit percentage does not lower the threshold; SPEC.md lowers request and byte limits only.
  • Judgement call: trap paths match exactly, case included; /wp-login.php/ and /%77p-login.php are not trapped.
  • Judgement call: the log's offence stays limit alone, since one request can be two offences at once.
  • Judgement call: a token refusal from SWWAF_ALLOW_NETS is an offence in its history, but not counted for the error burst.

Model: opus-5-5

Implements https://git.eeqj.de/sneak/smallwebwaf/issues/115. - `SWWAF_TRAP_PATHS`: a request whose path, as a `path` rule sees it, is exactly one of them is banned as a `ban` rule's match is, with `trap_path` in the notes. Checked after the rate limits and before the rule files, which it does not need. An entry not starting with `/`, or holding a `?`, stops the start. - `SWWAF_ERROR_BURST_THRESHOLD` (default `30`, or `off`): each request refused after a `block` or `ban` rule or a trap path, or with `401` for a missing or wrong token, is counted per client over a minute (`minute_refusals` in `clients.json`); one over the threshold bans as a broken limit does, with `limit_hit` `error_burst` and notes `kind` `refusals`. The app's answers and `SWWAF_ALLOW_NETS` clients are not counted. - A token refusal is the new offence `token_refused`; `smallwebwaf_offences_total` now counts every kind the history counts, not only `limit`. - `observe` mode counts what `enforce` mode would have refused, and raises the ban alert it would have. Disclosures: - Judgement call: a client's limit percentage does not lower the threshold; `SPEC.md` lowers request and byte limits only. - Judgement call: trap paths match exactly, case included; `/wp-login.php/` and `/%77p-login.php` are not trapped. - Judgement call: the log's `offence` stays `limit` alone, since one request can be two offences at once. - Judgement call: a token refusal from `SWWAF_ALLOW_NETS` is an offence in its history, but not counted for the error burst. Model: opus-5-5
clawbot self-assigned this 2026-10-08 06:00:23 +02:00
clawbot added 1 commit 2026-10-08 06:00:23 +02:00
SWWAF_TRAP_PATHS: a request whose path, as a path rule sees it, is one
of them is a clear sign of attack, banned as a ban rule's match is; the
ban's notes give its trap_path. Checked after the rate limits, before the
rule files.

SWWAF_ERROR_BURST_THRESHOLD (default 30, or off): more refusals in a
minute after a block or ban rule or a trap path, or for a missing or
wrong token, ban the client as a broken limit does. Counted in
clients.json's minute_refusals; limit_hit error_burst, notes kind
refusals.

A token refusal is now the offence token_refused, and
smallwebwaf_offences_total counts every kind the history does.

Judgement call: the threshold is not lowered by a client's limit percentage.

Model: opus-5-5
clawbot added the needs-review label 2026-10-08 06:00:28 +02:00
Author
Collaborator

Review passed.

  • Judgement call accepted: a client's limit percentage does not lower SWWAF_ERROR_BURST_THRESHOLD; SPEC.md lowers only the request and byte limits by it.
  • Judgement call accepted: a trap path matches the whole path exactly, case included, as a path rule sees it.
  • Judgement call accepted: the request log's offence stays limit alone.
  • Judgement call accepted: a token refusal from a client in SWWAF_ALLOW_NETS is an offence in its history but is not counted for the error burst, since such clients skip every check.

Model: opus-5-5

Review passed. - Judgement call accepted: a client's limit percentage does not lower `SWWAF_ERROR_BURST_THRESHOLD`; `SPEC.md` lowers only the request and byte limits by it. - Judgement call accepted: a trap path matches the whole path exactly, case included, as a `path` rule sees it. - Judgement call accepted: the request log's `offence` stays `limit` alone. - Judgement call accepted: a token refusal from a client in `SWWAF_ALLOW_NETS` is an offence in its history but is not counted for the error burst, since such clients skip every check. Model: opus-5-5
clawbot merged commit 54779f08de into next 2026-10-08 06:44:56 +02:00
clawbot deleted branch issue-115-trap-paths-error-burst 2026-10-08 06:44:57 +02:00
Sign in to join this conversation.