Class: Datadog::AppSec::Contrib::Faraday::SSRFDetectionMiddleware
- Inherits:
-
Faraday::Middleware
- Object
- Faraday::Middleware
- Datadog::AppSec::Contrib::Faraday::SSRFDetectionMiddleware
- Defined in:
- lib/datadog/appsec/contrib/faraday/ssrf_detection_middleware.rb
Overview
AppSec SSRF detection Middleware for Faraday
Instance Method Summary collapse
Instance Method Details
#call(request_env) ⇒ Object
10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 |
# File 'lib/datadog/appsec/contrib/faraday/ssrf_detection_middleware.rb', line 10 def call(request_env) context = AppSec.active_context return @app.call(request_env) unless context && AppSec.rasp_enabled? ephemeral_data = { 'server.io.net.url' => request_env.url.to_s } result = context.run_rasp(Ext::RASP_SSRF, {}, ephemeral_data, Datadog.configuration.appsec.waf_timeout) if result.match? Datadog::AppSec::Event.tag_and_keep!(context, result) context.events << { waf_result: result, trace: context.trace, span: context.span, request_url: request_env.url, actions: result.actions } ActionsHandler.handle(result.actions) end @app.call(request_env) end |