coreruleset / coreruleset/secrules_parsing
Handling `&` correctly
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 23
- Forks
- 9
- PR merge metrics
- No merged PRs in 30d
Description
Based on this PR it seems that some engines (libmodsecurity3) allow the & sign with each variables (eg. REQUEST_BODY_LENGTH) even it makes no sense (what about Coraza?). Apache2 reports a weird message: Error creating rule: The & modificator does not apply to non-collection variables. but allows & in front of REQUEST_BODY although it's not a collection either.
We should decide what way do we want to follow: keep the parser as is now or need some modification to make it more strict.
@theseion, @fzipi, @dune73 - what do you think about?
@M4tteoP, @jptosso - how Coraza handles this syntax?
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing the parser behavior discussed in the linked PR, then compare how Apache2, libmodsecurity3, and Coraza handle the \u0026 modifier on collection and non-collection variables. The issue is complete when the project’s intended strictness is decided and the parser behavior is aligned with that decision.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- security, tooling
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100