Skip to content

Add Fastly and CloudFlare headers to ASM attacks#5579

Merged
smola merged 1 commit intomasterfrom
smola/vendor-forward-headers
Jul 14, 2023
Merged

Add Fastly and CloudFlare headers to ASM attacks#5579
smola merged 1 commit intomasterfrom
smola/vendor-forward-headers

Conversation

@smola
Copy link
Copy Markdown
Member

@smola smola commented Jul 13, 2023

What Does This Do

Add fastly-client-ip, cf-connecting-ip and cf-connecting-ipv6 to the list of headers that will be sent to the backend when an attack is detected. These were already used for IP resolution, but were missing in the headers passlist.

Motivation

Additional Notes

See DataDog/system-tests#1401

@smola smola added the comp: asm waf Application Security Management (WAF) label Jul 13, 2023
@smola smola requested a review from a team as a code owner July 13, 2023 12:00
@smola smola requested a review from DDJavierSantos July 13, 2023 12:00
@pr-commenter
Copy link
Copy Markdown

pr-commenter Bot commented Jul 13, 2023

Benchmarks

Parameters

Baseline Candidate
commit 1.19.0-SNAPSHOT~a4a33e4a27 1.19.0-SNAPSHOT~b15412d860
config baseline candidate
See matching parameters
Baseline Candidate
module Agent Agent
parent None None

Summary

Found 0 performance improvements and 0 performance regressions! Performance is the same for 22 cases.

@smola smola force-pushed the smola/vendor-forward-headers branch from b15412d to cf755ac Compare July 13, 2023 16:11
@smola smola enabled auto-merge (squash) July 13, 2023 16:11
@smola smola merged commit eda6795 into master Jul 14, 2023
@smola smola deleted the smola/vendor-forward-headers branch July 14, 2023 09:43
@github-actions github-actions Bot added this to the 1.19.0 milestone Jul 14, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

comp: asm waf Application Security Management (WAF)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants