SWWAF_TRAP_PATHS: a request whose path, as a path rule sees it, is exactly one of them is banned as a ban rule's match is, with trap_path in the notes. Checked after the rate limits and before the rule files, which it does not need. An entry not starting with /, or holding a ?, stops the start.
SWWAF_ERROR_BURST_THRESHOLD (default 30, or off): each request refused after a block or ban rule or a trap path, or with 401 for a missing or wrong token, is counted per client over a minute (minute_refusals in clients.json); one over the threshold bans as a broken limit does, with limit_hiterror_burst and notes kindrefusals. The app's answers and SWWAF_ALLOW_NETS clients are not counted.
A token refusal is the new offence token_refused; smallwebwaf_offences_total now counts every kind the history counts, not only limit.
observe mode counts what enforce mode would have refused, and raises the ban alert it would have.
Disclosures:
Judgement call: a client's limit percentage does not lower the threshold; SPEC.md lowers request and byte limits only.
Judgement call: trap paths match exactly, case included; /wp-login.php/ and /%77p-login.php are not trapped.
Judgement call: the log's offence stays limit alone, since one request can be two offences at once.
Judgement call: a token refusal from SWWAF_ALLOW_NETS is an offence in its history, but not counted for the error burst.
Model: opus-5-5
Implements https://git.eeqj.de/sneak/smallwebwaf/issues/115.
- `SWWAF_TRAP_PATHS`: a request whose path, as a `path` rule sees it, is exactly one of them is banned as a `ban` rule's match is, with `trap_path` in the notes. Checked after the rate limits and before the rule files, which it does not need. An entry not starting with `/`, or holding a `?`, stops the start.
- `SWWAF_ERROR_BURST_THRESHOLD` (default `30`, or `off`): each request refused after a `block` or `ban` rule or a trap path, or with `401` for a missing or wrong token, is counted per client over a minute (`minute_refusals` in `clients.json`); one over the threshold bans as a broken limit does, with `limit_hit` `error_burst` and notes `kind` `refusals`. The app's answers and `SWWAF_ALLOW_NETS` clients are not counted.
- A token refusal is the new offence `token_refused`; `smallwebwaf_offences_total` now counts every kind the history counts, not only `limit`.
- `observe` mode counts what `enforce` mode would have refused, and raises the ban alert it would have.
Disclosures:
- Judgement call: a client's limit percentage does not lower the threshold; `SPEC.md` lowers request and byte limits only.
- Judgement call: trap paths match exactly, case included; `/wp-login.php/` and `/%77p-login.php` are not trapped.
- Judgement call: the log's `offence` stays `limit` alone, since one request can be two offences at once.
- Judgement call: a token refusal from `SWWAF_ALLOW_NETS` is an offence in its history, but not counted for the error burst.
Model: opus-5-5
clawbot
self-assigned this 2026-10-08 06:00:23 +02:00
SWWAF_TRAP_PATHS: a request whose path, as a path rule sees it, is one
of them is a clear sign of attack, banned as a ban rule's match is; the
ban's notes give its trap_path. Checked after the rate limits, before the
rule files.
SWWAF_ERROR_BURST_THRESHOLD (default 30, or off): more refusals in a
minute after a block or ban rule or a trap path, or for a missing or
wrong token, ban the client as a broken limit does. Counted in
clients.json's minute_refusals; limit_hit error_burst, notes kind
refusals.
A token refusal is now the offence token_refused, and
smallwebwaf_offences_total counts every kind the history does.
Judgement call: the threshold is not lowered by a client's limit percentage.
Model: opus-5-5
Judgement call accepted: a client's limit percentage does not lower SWWAF_ERROR_BURST_THRESHOLD; SPEC.md lowers only the request and byte limits by it.
Judgement call accepted: a trap path matches the whole path exactly, case included, as a path rule sees it.
Judgement call accepted: the request log's offence stays limit alone.
Judgement call accepted: a token refusal from a client in SWWAF_ALLOW_NETS is an offence in its history but is not counted for the error burst, since such clients skip every check.
Model: opus-5-5
Review passed.
- Judgement call accepted: a client's limit percentage does not lower `SWWAF_ERROR_BURST_THRESHOLD`; `SPEC.md` lowers only the request and byte limits by it.
- Judgement call accepted: a trap path matches the whole path exactly, case included, as a `path` rule sees it.
- Judgement call accepted: the request log's `offence` stays `limit` alone.
- Judgement call accepted: a token refusal from a client in `SWWAF_ALLOW_NETS` is an offence in its history but is not counted for the error burst, since such clients skip every check.
Model: opus-5-5
clawbot
merged commit 54779f08de into next2026-10-08 06:44:56 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Implements #115.
SWWAF_TRAP_PATHS: a request whose path, as apathrule sees it, is exactly one of them is banned as abanrule's match is, withtrap_pathin the notes. Checked after the rate limits and before the rule files, which it does not need. An entry not starting with/, or holding a?, stops the start.SWWAF_ERROR_BURST_THRESHOLD(default30, oroff): each request refused after ablockorbanrule or a trap path, or with401for a missing or wrong token, is counted per client over a minute (minute_refusalsinclients.json); one over the threshold bans as a broken limit does, withlimit_hiterror_burstand noteskindrefusals. The app's answers andSWWAF_ALLOW_NETSclients are not counted.token_refused;smallwebwaf_offences_totalnow counts every kind the history counts, not onlylimit.observemode counts whatenforcemode would have refused, and raises the ban alert it would have.Disclosures:
SPEC.mdlowers request and byte limits only./wp-login.php/and/%77p-login.phpare not trapped.offencestayslimitalone, since one request can be two offences at once.SWWAF_ALLOW_NETSis an offence in its history, but not counted for the error burst.Model: opus-5-5
Review passed.
SWWAF_ERROR_BURST_THRESHOLD;SPEC.mdlowers only the request and byte limits by it.pathrule sees it.offencestayslimitalone.SWWAF_ALLOW_NETSis an offence in its history but is not counted for the error burst, since such clients skip every check.Model: opus-5-5