Skip to content

feat: add example for content-type rule exclusion#286

Merged
fzipi merged 2 commits intocoreruleset:mainfrom
EsadCetiner:feat-add-content-type-rule-exclusion-example
May 1, 2026
Merged

feat: add example for content-type rule exclusion#286
fzipi merged 2 commits intocoreruleset:mainfrom
EsadCetiner:feat-add-content-type-rule-exclusion-example

Conversation

@EsadCetiner
Copy link
Copy Markdown
Member

Proposed changes

There isn't any examples in the documentation on how to safely allow additional Content Types without opening up a complete request body bypass. ModSecurity/Coraza relies on the Content Type header in order to parse a request body, and most users will either blindly disable the rule or add the forbidden content type to the list of allowed Content Types without fully understanding the impact.

Further comments

@EsadCetiner
Copy link
Copy Markdown
Member Author

@theseion @fzipi The CI job isn't running for this PR. I think this is related to hardening the jobs?

error: unable to contact snap store

Signed-off-by: Felipe Zipitria <felipe.zipitria@owasp.org>
@fzipi
Copy link
Copy Markdown
Member

fzipi commented May 1, 2026

I think you pushed your version of the theme/hugo-relearn that was older that the one upstream. Remember we are using submodules :)

@fzipi fzipi merged commit e5df77f into coreruleset:main May 1, 2026
1 check passed
@EsadCetiner EsadCetiner deleted the feat-add-content-type-rule-exclusion-example branch May 1, 2026 21:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants