HarperFast / HarperFast/harper-pro
[Epic] WAF: rules, compliance, and observability
- Dominant language
- JavaScript
- Stars
- 3
- Forks
- 0
- Avg merge
- 1d 21h
- Merged PRs (30d)
- 80
Description
Harper's web application firewall: the middleware, its rule surface, and what it must do to be usable as an assessed control.
## Scope
**In:** WAF middleware and rule evaluation, audit logging and redaction of what it blocks, rule-change trails, monitor mode, health signal, and the starter rule pack.
**Out:** general HTTP security headers (#1660) and authentication/authorization enforcement (#1646). The WAF sits in front of those, but a defect in either is theirs.
## Why
Spans both repos — the middleware is in `harper`, the compliance definition-of-done in `harper-pro` — which is exactly the kind of work that goes untracked when it has no parent.
_Created during backlog triage. Child issues keep their own priorities and milestones._
Contributor guide
Research direction
Start by locating the WAF middleware and rule-evaluation entry points in harper, then read the compliance definition of done in harper-pro. Map the stated scope across both repositories, including audit logging, redaction, rule-change trails, monitor mode, health signals, and the starter rule pack; done means the epic's child issues cover these requirements without overlapping #1660 or #1646.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- observability, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100