Class: Datadog::AppSec::Contrib::Faraday::SSRFDetectionMiddleware
- Inherits:
-
Faraday::Middleware
- Object
- Faraday::Middleware
- Datadog::AppSec::Contrib::Faraday::SSRFDetectionMiddleware
- Defined in:
- lib/datadog/appsec/contrib/faraday/ssrf_detection_middleware.rb
Overview
AppSec SSRF detection Middleware for Faraday
Instance Method Summary collapse
Instance Method Details
#call(env) ⇒ Object
13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 |
# File 'lib/datadog/appsec/contrib/faraday/ssrf_detection_middleware.rb', line 13 def call(env) context = AppSec.active_context return @app.call(env) unless context && AppSec.rasp_enabled? timeout = Datadog.configuration.appsec.waf_timeout ephemeral_data = { 'server.io.net.url' => env.url.to_s, 'server.io.net.request.method' => env.method.to_s.upcase, 'server.io.net.request.headers' => env.request_headers.transform_keys(&:downcase) } result = context.run_rasp(Ext::RASP_SSRF, {}, ephemeral_data, timeout, phase: Ext::RASP_REQUEST_PHASE) handle(result, context: context) if result.match? @app.call(env).on_complete { |response_env| on_complete(response_env, context: context) } end |