ignore native modsec rules that were either pass or allow (#2684)
This commit is contained in:
parent
fd309134a2
commit
e452dc80bd
1 changed files with 2 additions and 2 deletions
|
@ -202,8 +202,8 @@ func (r *AppsecRunner) AccumulateTxToEvent(evt *types.Event, req *appsec.ParsedR
|
|||
})
|
||||
|
||||
for _, rule := range req.Tx.MatchedRules() {
|
||||
if rule.Message() == "" {
|
||||
r.logger.Tracef("discarding rule %d", rule.Rule().ID())
|
||||
if rule.Message() == "" || rule.DisruptiveAction() == "pass" || rule.DisruptiveAction() == "allow" {
|
||||
r.logger.Tracef("discarding rule %d (action: %s)", rule.Rule().ID(), rule.DisruptiveAction())
|
||||
continue
|
||||
}
|
||||
kind := "outofband"
|
||||
|
|
Loading…
Reference in a new issue