Skip to content

Add new linting rule for preventing SecRule directives to remove targets from REQUEST_COOKIES #112

@fzipi

Description

@fzipi

Based on coreruleset/coreruleset#4378, we are moving cookie exclusions from SecRules to a post CRS file with SecRuleUpdateTargetById directives instead.

requirements

  • check that SecRule directives don't have the old behavior: !REQUEST_COOKIES should not be allowed as target

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions