Class: Datadog::AppSec::Component
- Inherits:
-
Object
- Object
- Datadog::AppSec::Component
- Defined in:
- lib/datadog/appsec/component.rb
Overview
Core-pluggable component for AppSec
Instance Attribute Summary collapse
-
#security_engine ⇒ Object
readonly
Returns the value of attribute security_engine.
-
#telemetry ⇒ Object
readonly
Returns the value of attribute telemetry.
Class Method Summary collapse
Instance Method Summary collapse
-
#initialize(security_engine:, telemetry:) ⇒ Component
constructor
A new instance of Component.
- #reconfigure! ⇒ Object
- #reconfigure_lock(&block) ⇒ Object
- #shutdown! ⇒ Object
Constructor Details
#initialize(security_engine:, telemetry:) ⇒ Component
Returns a new instance of Component.
74 75 76 77 78 79 |
# File 'lib/datadog/appsec/component.rb', line 74 def initialize(security_engine:, telemetry:) @security_engine = security_engine @telemetry = telemetry @mutex = Mutex.new end |
Instance Attribute Details
#security_engine ⇒ Object (readonly)
Returns the value of attribute security_engine.
72 73 74 |
# File 'lib/datadog/appsec/component.rb', line 72 def security_engine @security_engine end |
#telemetry ⇒ Object (readonly)
Returns the value of attribute telemetry.
72 73 74 |
# File 'lib/datadog/appsec/component.rb', line 72 def telemetry @telemetry end |
Class Method Details
.build_appsec_component(settings, telemetry:) ⇒ Object
13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 |
# File 'lib/datadog/appsec/component.rb', line 13 def build_appsec_component(settings, telemetry:) return if !settings.respond_to?(:appsec) || !settings.appsec.enabled ffi_version = Gem.loaded_specs['ffi']&.version unless ffi_version Datadog.logger.warn('FFI gem is not loaded, AppSec will be disabled.') telemetry.error('AppSec: Component not loaded, due to missing FFI gem') return end if Gem::Version.new(RUBY_VERSION) >= Gem::Version.new('3.3') && ffi_version < Gem::Version.new('1.16.0') Datadog.logger.warn( 'AppSec is not supported in Ruby versions above 3.3.0 when using `ffi` versions older than 1.16.0, ' \ 'and will be forcibly disabled due to a memory leak in `ffi`. ' \ 'Please upgrade your `ffi` version to 1.16.0 or higher.' ) telemetry.error('AppSec: Component not loaded, ffi version is leaky with ruby > 3.3.0') return end require_libddwaf(telemetry: telemetry) Datadog::AppSec::WAF.logger = Datadog.logger if Datadog.logger.debug? && settings.appsec.waf_debug # We want to always instrument user events when AppSec is enabled. # There could be cases in which users use the DD_APPSEC_ENABLED Env variable to # enable AppSec, in that case, Devise is already instrumented. # In the case that users do not use DD_APPSEC_ENABLED, we have to instrument it, # hence the lines above. devise_integration = Datadog::AppSec::Contrib::Devise::Integration.new settings.appsec.instrument(:devise) unless devise_integration.patcher.patched? security_engine = SecurityEngine::Engine.new(appsec_settings: settings.appsec, telemetry: telemetry) new(security_engine: security_engine, telemetry: telemetry) rescue Datadog.logger.warn('AppSec is disabled, see logged errors above') nil end |
Instance Method Details
#reconfigure! ⇒ Object
81 82 83 84 85 |
# File 'lib/datadog/appsec/component.rb', line 81 def reconfigure! @mutex.synchronize do security_engine.reconfigure! end end |
#reconfigure_lock(&block) ⇒ Object
87 88 89 |
# File 'lib/datadog/appsec/component.rb', line 87 def reconfigure_lock(&block) @mutex.synchronize(&block) end |
#shutdown! ⇒ Object
91 92 93 94 95 96 |
# File 'lib/datadog/appsec/component.rb', line 91 def shutdown! @mutex.synchronize do security_engine.finalize! @security_engine = nil end end |