HarperFast / HarperFast/harper-pro

[Epic] WAF: rules, compliance, and observability

Open
#672 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
3
Forks
0
Avg merge
1d 21h
Merged PRs (30d)
80

Description

Harper's web application firewall: the middleware, its rule surface, and what it must do to be usable as an assessed control.

## Scope

**In:** WAF middleware and rule evaluation, audit logging and redaction of what it blocks, rule-change trails, monitor mode, health signal, and the starter rule pack.

**Out:** general HTTP security headers (#1660) and authentication/authorization enforcement (#1646). The WAF sits in front of those, but a defect in either is theirs.

## Why

Spans both repos — the middleware is in `harper`, the compliance definition-of-done in `harper-pro` — which is exactly the kind of work that goes untracked when it has no parent.

_Created during backlog triage. Child issues keep their own priorities and milestones._

Contributor guide

Open the contributing guide

Research direction

Start by locating the WAF middleware and rule-evaluation entry points in harper, then read the compliance definition of done in harper-pro. Map the stated scope across both repositories, including audit logging, redaction, rule-change trails, monitor mode, health signals, and the starter rule pack; done means the epic's child issues cover these requirements without overlapping #1660 or #1646.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
observability, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.