[Feature request] Expose Modsecurity variables to ngx/LUA
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 25/100
- Issue type
- Feature
- Clarity
- Needs clarification
- Activity status
- Stale
- Tech stack
- nginx
- Domain
- security
Research direction
Start by tracing how the connector exposes variables to ngx.var and how the ModSecurity transaction is represented. Determine whether $modsecurity_tx, $modsecurity_env, and $modsecurity_geo, plus matched-rule metadata, are available to expose. Done means the requested transaction data and matched-rule information can be accessed from ngx/LUA.
Written by the indexing model from the issue text.
Description
It would be nice to have the variables of Modsecurity exposed to ngx/LUA (ngx.var).
So we can do some treatment on the transaction (eg. increment a Prometheus counter, set headers, ...)
Something like having the variables $modsecurity_tx, $modsecurity_env, $modsecurity_geo available.
Also having the possibility to get all the rules that matched and their metadata (I'm not sure in which var they are stored).
Do you think that's feasible ?
- Dominant language
- Perl
- Stars
- 1.9k
- Forks
- 312
- PR merge metrics
- No merged PRs in 30d
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from owasp-modsecurity/ModSecurity-nginx
-
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
-
:1st_place_medal: good first issue enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
owasp-modsecurity/ModSecurity-nginx#359 · 3 comments ·
-
Module logs version of libmodsecurity headers it was built against, not dynamically linked version Open
Difficulty 5/5 Over a week Newbie friendliness 35/100
owasp-modsecurity/ModSecurity-nginx#383 · 1 comment ·
-
Difficulty 4/5 3-5 days Newbie friendliness 35/100
owasp-modsecurity/ModSecurity-nginx#375 · 2 comments ·
-
Difficulty 3/5 1-2 days Newbie friendliness 55/100
owasp-modsecurity/ModSecurity-nginx#365 · 2 comments ·
All issues in owasp-modsecurity/ModSecurity-nginx
Similar issues
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
stfc/cloud-image-builders#218 ·
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
0.kind: bug
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
-
Role::Serializer: class-method deserialize failure raises Class::XSAccessor, masking the real error OpenBug
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
PerlDancer/Dancer2#1837 · 1 comment ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100