mirror of
https://github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin.git
synced 2026-09-02 12:28:50 +02:00
* Do not consider body unreadable when it's http.NoBody Fix #351 * 🐛 appsec: only drop unreadable bodies for methods that carry one Gate the crowdsecAppsecUnreadableBodyBlock drop on the request method, mirroring the reference lua-cs-bouncer METHODS_WITH_BODY list (POST/PUT/PATCH/DELETE). Browser GETs over HTTP/3 never carry a Content-Length (quic-go always wraps the stream in a non-nil body with ContentLength -1), so they were all wrongly dropped; they are now forwarded to appsec headers-only, while gRPC streams (always POST) stay droppable. Fix #351 Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * 🍱 add test and remove useless comment * 🍱 add test for GET with unreadable body * 🍱 fix log * 🍱 fix test --------- Co-authored-by: mhx <mathieu@hanotaux.fr> Co-authored-by: Claude Fable 5 <noreply@anthropic.com> Co-authored-by: maxlerebourg <maxlerebourg@gmail.com>
33 lines
880 B
YAML
33 lines
880 B
YAML
http:
|
|
routers:
|
|
r:
|
|
rule: "PathPrefix(`/foo`)"
|
|
entryPoints:
|
|
- web
|
|
service: backend
|
|
middlewares:
|
|
- bouncer
|
|
services:
|
|
backend:
|
|
loadBalancer:
|
|
servers:
|
|
- url: "@@BACKEND_URL@@"
|
|
middlewares:
|
|
bouncer:
|
|
plugin:
|
|
bouncer:
|
|
enabled: "true"
|
|
# IP bouncing disabled — this scenario exercises AppSec only.
|
|
crowdsecMode: appsec
|
|
crowdsecLapiScheme: http
|
|
crowdsecLapiHost: "@@LAPI_HOST@@"
|
|
crowdsecLapiKey: "@@APIKEY@@"
|
|
crowdsecAppsecEnabled: "true"
|
|
crowdsecAppsecFailureBlock: "true"
|
|
crowdsecAppsecBodyLimit: 4
|
|
crowdsecAppsecUnreachableBlock: "false"
|
|
crowdsecAppsecScheme: http
|
|
crowdsecAppsecHost: "@@APPSEC_HOST@@"
|
|
forwardedHeadersTrustedIps:
|
|
- "127.0.0.1/32"
|