Class: Datadog::AppSec::Contrib::Rack::RequestBodyMiddleware

Inherits:
Object
  • Object
show all
Defined in:
lib/datadog/appsec/contrib/rack/request_body_middleware.rb

Overview

Rack request body middleware for AppSec This should be inserted just below Rack::JSONBodyParser or legacy Rack::PostBodyContentTypeParser from rack-contrib

Instance Method Summary collapse

Constructor Details

#initialize(app, opt = {}) ⇒ RequestBodyMiddleware

TODO: opt is never used, it can probably be safely removed



16
17
18
# File 'lib/datadog/appsec/contrib/rack/request_body_middleware.rb', line 16

def initialize(app, opt = {}) # steep:ignore DifferentMethodParameterKind
  @app = app
end

Instance Method Details

#call(env) ⇒ Object



20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
# File 'lib/datadog/appsec/contrib/rack/request_body_middleware.rb', line 20

def call(env)
  context = env[Datadog::AppSec::Ext::CONTEXT_KEY]

  return @app.call(env) unless context

  # TODO: handle exceptions, except for @app.call

  http_response = nil #: Rack::response?
  interrupt_params = catch(::Datadog::AppSec::Ext::INTERRUPT) do
    http_response, _request = Instrumentation.gateway.push("rack.request.body", Gateway::Request.new(env)) do
      @app.call(env)
    end

    nil
  end

  return AppSec::Response.from_interrupt_params(interrupt_params, env["HTTP_ACCEPT"]).to_rack if interrupt_params

  # Steep can't see that the catch block always populates http_response
  # when no interrupt is thrown.
  http_response #: Rack::response
end