Class: Datadog::AppSec::Contrib::Faraday::SSRFDetectionMiddleware

Inherits:
Faraday::Middleware
  • Object
show all
Defined in:
lib/datadog/appsec/contrib/faraday/ssrf_detection_middleware.rb

Overview

AppSec SSRF detection Middleware for Faraday

Instance Method Summary collapse

Instance Method Details

#call(env) ⇒ Object



13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
# File 'lib/datadog/appsec/contrib/faraday/ssrf_detection_middleware.rb', line 13

def call(env)
  context = AppSec.active_context
  return @app.call(env) unless context && AppSec.rasp_enabled?

  timeout = Datadog.configuration.appsec.waf_timeout
  ephemeral_data = {
    'server.io.net.url' => env.url.to_s,
    'server.io.net.request.method' => env.method.to_s.upcase,
    'server.io.net.request.headers' => env.request_headers.transform_keys(&:downcase)
  }

  result = context.run_rasp(Ext::RASP_SSRF, {}, ephemeral_data, timeout, phase: Ext::RASP_REQUEST_PHASE)
  handle(result, context: context) if result.match?

  @app.call(env).on_complete { |response_env| on_complete(response_env, context: context) }
end