Urgent.News

What's breaking now, across thousands of outlets.

Tech

When Cloudflare WAF detections fail, choose a rule response for each route

A security detection can fail before it decides whether a request is safe. That is a different event from a detection matching an attack. If your app depends on edge screening for a sensitive route, what happens when the detector reports an error? Cloudflare's new cf.appsec.request.failed_detections field gives your Rules engine the detection IDs that reported failures for a request. It does not…

Cloudflare's new cf.appsec.request.failed_detections field provides security teams with detection IDs for failed requests on sensitive routes. This does not alter the detectors' behavior, but allows the Rules engine to make an explicit choice on how to handle these failures. A failed detection is distinct from a detection match; the former indicates a supported detector could not complete normally, while the latter means a detector recognized a condition it was designed to detect.

The field exposes the latter to supported rules and is not a global fail-open or fail-closed switch. It serves as a signal for your policy to inspect, not as a default behavior. The field is an array of strings, including IDs for failures reported by various detectors. It is available on all plans but only includes detections and rule features your plan supports.

The field is evaluated before custom rules and can be used in specific rule types at zone and account level, rate limiting rules at zone and account level, and request-header rules at zone level. The choice of rule type depends on the scope and intended action. When using the field, separate the detector's failure from the policy decision.

Treat it as a signal, not a verdict. An empty array means no failures were reported. An example of a rule expression could be len(cf.appsec.request.failed_detections) gt 0 to match any reported failure. Always validate before enforcing a new failure policy and consider the type of request and potential impact.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

I Turned My Repetitive CSV Checks Into a Python CLI

I kept running the same checks whenever I opened a new CSV or Excel file. Missing values. Duplicate rows. Mixed numeric and text values. Bad dates. Columns that never change.

  • Shahed Razavi created Data Quality Detective (dqdetect) Python CLI tool
  • Analyzes datasets for issues like missing values, duplicates, mixed types, outliers
  • Generates Markdown and HTML reports with suggestions for further inspection

48-Hour Field Notes: I Would Fingerprint the Locale Before I Blame the Fixture

Have you ever watched a text fixture pass on your laptop and then fail on a clean remote job? I keep meeting that surprise when the file looks identical and the decoder still disagrees with it.

  • Record locale before diagnosing text fixture failures.
  • Consider codec as first suspect for UnicodeDecodeError.
  • Compare free model and free server environments.

More from Saturday 10 October →