owasp-modsecurity / owasp-modsecurity/ModSecurity

Expand macro functionality

Open
#215 5 comments 0 reactions 1 assignee View on GitHub

@zimmerle is already working on this.

Since Oct 17, 2013.

2.x 3.x enhancement TBF by libmodsec
Dominant language
C++
Stars
9.8k
Forks
1.8k
Avg merge
2h 46m
Merged PRs (30d)
1

Description

MODSEC-64: Some ideas for making macros more useful:

  • %{&COLLECTION} -- count of COLLECTION variables
  • %{t(lowercase,ARGS)} -- Allow transformations in macros
  • %{rand(N)} -- Allow other functions like random values (should be extendible via API)
  • Allow defining macros -- SecMacro FOO "foo"
    These are config time macros vs runtime. Maybe use %{{CONFIG_MACRO}}?
  • Allow defining macros with parameters -- SecMacro FOO(bar) "foo%{bar}"
  • Allow macro expansion in TARGETS (at least config-time) -- ARGS|%{{CUSTOM_FIELDS}}
    {noformat}
    SecMacro CUSTOM_TARGETS "ARGS|!ARGS:description"
    ...
    SecRule %{{CUSTOM_TARGETS}} "foo" "..."
    {noformat}

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.