Selaa lähdekoodia

Merge pull request #433 from mdr-engineering/feature/ftd_MSOCI-1988_GitHubRules

Adds FW Exceptions for GitHub WAF
Frederick Damstra 3 vuotta sitten
vanhempi
sitoutus
97cab3338c
1 muutettua tiedostoa jossa 6 lisäystä ja 1 poistoa
  1. 6 1
      base/github/elb.tf

+ 6 - 1
base/github/elb.tf

@@ -37,7 +37,12 @@ module "elb" {
     "AWSManagedRulesUnixRuleSet"            = false # Irrelevant, module is disabled
   }
 
-  excluded_rules_AWSManagedRulesCommonRuleSet = ["SizeRestrictions_BODY"]
+  excluded_rules_AWSManagedRulesCommonRuleSet = [
+    "SizeRestrictions_BODY",               # SAML auth
+    "RestrictedExtensions_URIPATH",        # Lots of prohibited extensions, e.g. props.conf
+    "RestrictedExtensions_QueryArguments", # Again, prohibited extensions don't work here
+
+  ]
   #excluded_rules_AWSManagedRulesAmazonIpReputationList = []
   #excluded_rules_AWSManagedRulesKnownBadInputsRuleSet = []
   #excluded_rules_AWSManagedRulesSQLiRuleSet = [] # Module disabled