20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
|
# File 'lib/datadog/appsec/contrib/rails/gateway/watcher.rb', line 20
def watch_request_action(gateway = Instrumentation.gateway)
gateway.watch('rails.request.action', :appsec) do |stack, gateway_request|
block = false
event = nil
scope = gateway_request.env[Datadog::AppSec::Ext::SCOPE_KEY]
AppSec::Reactive::Operation.new('rails.request.action') do |op|
Rails::Reactive::Action.subscribe(op, scope.processor_context) do |result|
if result.status == :match
event = {
waf_result: result,
trace: scope.trace,
span: scope.service_entry_span,
request: gateway_request,
actions: result.actions
}
if scope.service_entry_span
scope.service_entry_span.set_tag('appsec.blocked', 'true') if result.actions.include?('block')
scope.service_entry_span.set_tag('appsec.event', 'true')
end
scope.processor_context.events << event
end
end
block = Rails::Reactive::Action.publish(op, gateway_request)
end
next [nil, [[:block, event]]] if block
ret, res = stack.call(gateway_request.request)
if event
res ||= []
res << [:monitor, event]
end
[ret, res]
end
end
|