{"repo":"corazawaf/coraza-caddy","free":true,"listed":false,"github":"https://github.com/corazawaf/coraza-caddy","clone":"git clone https://github.com/corazawaf/coraza-caddy.git","description":"OWASP Coraza middleware for Caddy. It provides Web Application Firewall capabilities","language":"Go","stars":663,"topics":["caddy","caddyserver","coreruleset","go","golang","owasp","security","waf","webapplicationfirewall"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"Coraza WAF Caddy Module OWASP Coraza Caddy Module provides Web Application Firewall capabilities for Caddy. OWASP Coraza WAF is 100% compatible with OWASP Coreruleset and Modsecurity syntax. CRS Documentation If you’re looking for installation guidance, tuning, false-positive handling, or deployment best practices for CRS, refer to the official OWASP CRS documentation. https://coreruleset.org/docs/ This repository focuses on Coraza integration and runtime behavior rather than maintaining CRS rule documentation. Getting started go run mage.go -l lists all the available commands: Plugin syntax Sample usage: Important: order coraza waf first must be always included in your Caddyfile for Coraza module to work Build Caddy with Coraza WAF Run: Testing You may run the test suite by executing: Using OWASP Core Ruleset You can load OWASP CRS by passing the field load owasp crs and then load the CRS files in the directives as described in the coraza-coreruleset documentation. Running Example Docker Local Respond with custom message or HTML page In order to respond with a custom message or HTML page, you can take advantage of handle errors directive: or It is possible to use the templates directive to render data dynamically. Take a look at example/403.html file.","default_branch":null,"files":null,"tree":[],"storefront":"/r/corazawaf","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/corazawaf/coraza-caddy/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}