check / check (push) Waiting to run
SWWAF_WAF_BODY_LIMIT (default off, at most 1G) has the Core Rule Set read form data and multipart up to the limit, the rest streaming on, and JSON and XML (with +json, text/json and +xml) no larger than it. The part read is held for the app. A size or time limit met while reading ends the request. Content-Encoding is refused again on these kinds. A body Coraza cannot parse, or a multipart body failing its strict checks, adds 5, but not a multipart body reaching the limit. Coraza is built with no_fs_access, so writes no file. Rule 900300 moves to phase 2. Judgement call: Content-Encoding is refused on a JSON or XML body too large to read, as SPEC.md allows. Model: opus-5-5
19 lines
599 B
Python
Executable File
19 lines
599 B
Python
Executable File
#!/bin/sh
|
|
# script/build: build bin/smallwebwaf on the host, with Go installed, for
|
|
# working on the code by hand. The version it reports comes from git, as
|
|
# in script/docker, and the no_fs_access tag is the Dockerfile's.
|
|
set -eu
|
|
|
|
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
|
ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
|
|
|
|
main() {
|
|
cd "$ROOT"
|
|
version="$(git describe --tags --always --dirty 2>/dev/null || true)"
|
|
[ -n "$version" ] || version="unknown"
|
|
go build -tags no_fs_access -trimpath -ldflags "-X main.Version=$version" \
|
|
-o bin/smallwebwaf ./cmd/smallwebwaf
|
|
}
|
|
|
|
main "$@"
|