Based on coreruleset/coreruleset#4378, we are moving cookie exclusions from SecRules to a post CRS file with SecRuleUpdateTargetById directives instead.
requirements
- check that
SecRule directives don't have the old behavior: !REQUEST_COOKIES should not be allowed as target