瀏覽代碼

Adds FW Exceptions for GitHub WAF

To be tagged v4.2.12
Fred Damstra [afs macbook] 3 年之前
父節點
當前提交
b30d7b0e55
共有 1 個文件被更改,包括 6 次插入1 次删除
  1. 6 1
      base/github/elb.tf

+ 6 - 1
base/github/elb.tf

@@ -37,7 +37,12 @@ module "elb" {
     "AWSManagedRulesUnixRuleSet"            = false # Irrelevant, module is disabled
   }
 
-  excluded_rules_AWSManagedRulesCommonRuleSet = ["SizeRestrictions_BODY"]
+  excluded_rules_AWSManagedRulesCommonRuleSet = [
+    "SizeRestrictions_BODY",               # SAML auth
+    "RestrictedExtensions_URIPATH",        # Lots of prohibited extensions, e.g. props.conf
+    "RestrictedExtensions_QueryArguments", # Again, prohibited extensions don't work here
+
+  ]
   #excluded_rules_AWSManagedRulesAmazonIpReputationList = []
   #excluded_rules_AWSManagedRulesKnownBadInputsRuleSet = []
   #excluded_rules_AWSManagedRulesSQLiRuleSet = [] # Module disabled