Git Product home page Git Product logo

casbin / caswaf Goto Github PK

View Code? Open in Web Editor NEW
298.0 5.0 17.0 812 KB

HTTP & OAuth Gateway and Web Application Firewall (WAF) based on ModSecurity, online demo: https://door.caswaf.com

Home Page: https://caswaf.org

License: Apache License 2.0

Go 56.40% Dockerfile 0.27% JavaScript 40.55% HTML 0.66% CSS 1.75% Less 0.37%
firewall gateway http oauth proxy waf web-application-firewall modsecurity modsecurity-core-rule-set

caswaf's Issues

Feature: Adding contributors section to the README.md file

There is no Contributors section in readme file .
As we know Contributions are what make the open-source community such an amazing place to learn, inspire, and create.
The Contributors section in a README.md file is important as it acknowledges and gives credit to those who have contributed to a project, fosters community and collaboration, adds transparency and accountability, and helps document the project's history for current and future maintainers. It also serves as a form of recognition, motivating contributors to continue their efforts.
contributors

[feature] add condition feature

Condition should be added to CasWAF as first-class object (Go struct, CURD, list page, edit page, etc.)

Condition can be:

  1. Always true
  2. WAF rule matched
  3. IP whitelist/blacklist
  4. UA whitelist/blacklist
  5. Composite conditions like requestUrl.startsWith("/attack") && method == "POST || WAF rule matched"

Manage ModSecurity process in Go code

ModSecurity 3.x can be deployed manually via native or Docker ways: https://github.com/SpiderLabs/ModSecurity

CasWAF needs to use Go code to control the start/stop/configure of ModSecurity:

  1. Download ModSecurity source code/Docker image
  2. Modify the config of ModSecurity
  3. Start/stop the process of ModSecurity
  4. Do monitoring and logging for ModSecurity events

First step would be, writing a Go test to download ModSecurity and run it up

Change the method of work

In this project, is it possible to send packages to caswaf without setting a proxy on the browser or the operating system and only through the URL of the website (ex: caswaf.org/casnode and redirect base on convert casnode to casnode.org), in order to reach the goal in terms of the project's productivity and not disrupting other user's work, etc.?
If it is technically feasible, what way do you suggest?

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.