check / check (push) Waiting to run
Every *.rules file in SWWAF_RULES_DIR is read at start and on each change, and each request is checked against the rules after the rate limits: log notes a match, block refuses with 403, ban refuses and bans the netblock for SWWAF_ATTACK_BAN_DURATION, made permanent by its next request or clear sign of attack. path, query and uri are matched as the request line sent them. bans.json gains each ban's cause, and ban notes count earlier bans by cause. The image ships 00-default.rules. Judgement call: a header sent twice is matched with its values joined by ", ". Judgement call: SWWAF_MAX_BAN_DURATION does not cap a ban for an attack. Not in this unit: offences for rule matches, with the error burst. Model: opus-5-5
27 lines
772 B
Bash
Executable File
27 lines
772 B
Bash
Executable File
#!/bin/sh
|
|
# script/run: build bin/smallwebwaf with script/build and run it, with
|
|
# the settings in the environment. Unless SWWAF_STATE_DIR is set, the
|
|
# state files go in bin/state, beside the binary, and unless
|
|
# SWWAF_RULES_DIR is set, the rule files are those of share/rules.d,
|
|
# which the image ships.
|
|
set -eu
|
|
|
|
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
|
ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
|
|
|
|
main() {
|
|
"$SCRIPT_DIR/build"
|
|
if [ -z "${SWWAF_STATE_DIR+set}" ]; then
|
|
SWWAF_STATE_DIR="$ROOT/bin/state"
|
|
export SWWAF_STATE_DIR
|
|
mkdir -p "$SWWAF_STATE_DIR"
|
|
fi
|
|
if [ -z "${SWWAF_RULES_DIR+set}" ]; then
|
|
SWWAF_RULES_DIR="$ROOT/share/rules.d"
|
|
export SWWAF_RULES_DIR
|
|
fi
|
|
exec "$ROOT/bin/smallwebwaf"
|
|
}
|
|
|
|
main "$@"
|