check / check (push) Waiting to run
SWWAF_WAF_BODY_LIMIT (default off) has the Core Rule Set read form data and multipart up to the limit, the rest streaming on, and JSON and XML no larger than it; other bodies pass uninspected. The part read is held and sent to the app ahead of the rest. The client has SWWAF_CLIENT_REQUEST_TIMEOUT to send it, and a size or time limit met while it is read ends the request before it reaches the app. Content-Encoding is refused again on those four kinds. Rule 900300 moves to phase 2, so it counts form and JSON fields past Coraza's 1000 too. Judgement call: Content-Encoding is refused on a JSON or XML body too large to be read, which SPEC.md allows. Model: opus-5-5