34 lines
1.3 KiB
Plaintext
34 lines
1.3 KiB
Plaintext
# ---------------------------------------------------------------------------
|
|
# Local Coraza overrides.
|
|
#
|
|
# The recommended base config and the OWASP CRS are loaded from the Caddyfile
|
|
# via the `load_owasp_crs` directive (which exposes them under the
|
|
# @coraza.conf-recommended, @crs-setup.conf.example, and @owasp_crs/* aliases).
|
|
#
|
|
# Add per-site exceptions / tuning below.
|
|
# ---------------------------------------------------------------------------
|
|
|
|
# Engine in blocking mode.
|
|
SecRuleEngine On
|
|
|
|
# Reasonable request-body limits for a static blog.
|
|
SecRequestBodyLimit 13107200
|
|
SecRequestBodyNoFilesLimit 131072
|
|
SecRequestBodyLimitAction Reject
|
|
|
|
# Drop very noisy false-positives on static asset paths.
|
|
SecRule REQUEST_URI "@beginsWith /_astro/" \
|
|
"id:1000,phase:1,pass,nolog,ctl:ruleEngine=Off"
|
|
SecRule REQUEST_URI "@beginsWith /fonts/" \
|
|
"id:1001,phase:1,pass,nolog,ctl:ruleEngine=Off"
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Audit log — every blocked request gets an entry in serial format that
|
|
# fail2ban tails on the host (mounted at /var/log/caddy/coraza-audit.log).
|
|
# ---------------------------------------------------------------------------
|
|
SecAuditEngine RelevantOnly
|
|
SecAuditLogRelevantStatus "^(?:5|4(?!04))"
|
|
SecAuditLogParts ABIJDEFHZ
|
|
SecAuditLogType Serial
|
|
SecAuditLog /var/log/caddy/coraza-audit.log
|