Install the Process Request Data Into Headers integration
Install Process Request Data Into Headers from Azion Marketplace and run it on a firewall to turn request body fields into request headers.
You install the Process Request Data Into Headers integration from Azion Marketplace and run it on a Firewall, from Azion Console. The function converts the fields of a request body into request headers, and it stops a request when a request body field is empty. With regex, you validate that a field exists and that it matches a pattern, and you can use any behavior instead of a fixed Deny Request.
Five objects have to exist before a request is processed: the installed function, a firewall carrying the Functions module, a function instance, a Rules Engine rule with the Run Function behavior, and a workload deployment bound to the firewall. Each section below creates one of them.
Prerequisites
- An Azion account. To sign in, refer to How to access Azion Console.
- An application served by a workload, whose deployment you bind to the firewall in the last section.
- The Azion CLI installed and authorized, for the last section.
- Turning on a product or a module can generate usage costs. For more information, refer to Pricing.
Install the integration
The function is installed once per account. To install it:
Access Azion Console > Marketplace.
Enter Process Request Data Into Headers in the Search on Marketplace field, then select the integration’s card. Browsing the cards and the categories reaches the same page.
The card shows Successfully installed! and Latest version installed!, and the function appears in the Function list of the Create Instance drawer.
Create the firewall
The firewall is where the function is instanced and where the rule that runs it lives. To create one:
Access Azion Console > Firewalls, then create a firewall.
In the General section, enter a Name. For example: request-data-firewall.
In the Modules section, turn on the Functions switch.
The firewall shows a Functions Instances tab while the Functions module stays on. To use an existing firewall instead, turn on its Functions module and save it. For every setting on this form, refer to Set a firewall’s main settings.
Create the function instance
The instance connects the installed function to your firewall. To create it:
In Firewalls, select your firewall, then select the Functions Instances tab.
A firewall that has no instance shows the same action as Function Instance. The Create Instance drawer opens.
In Name, enter a name. For example: process-request-data.
In Function, select the Process Request Data Into Headers function. The list holds only the functions that run on a firewall.
The instance is listed in the Functions Instances tab.
Arguments
The function takes no arguments. You can test it with curl after the rule runs it.
Request examples
When a request has a valid Content-Type header and a valid request body, the function converts the body fields into headers. The function also supports nested object data, and a hyphen separates each level of the object in the header name.
| Curl command | Request headers added by the function |
|---|---|
curl https://mydomain/function | X-Body-Error": "CT001 |
curl -H "Content-Type: application/x-www-form-urlencoded" --request POST --data 'param1=v1¶m2=v2¶m3=v3' https://mydomain/function | X-Body-Param1": "v1", X-Body-Param2": "v2", X-Body-Param3": "v3" |
curl -H "Content-Type: application/json" --request POST --data '{"my_data": {"abc": {"def": {"g": "xyz","h": false,"e": null}}, "number": 1}}' https://mydomain/function | X-Body-My-Data-Abc-Def-G": "xyz", X-Body-My-Data-Abc-Def-H": "false", X-Body-My-Data-Number": "1" |
curl -H "Content-Type: text/plain" --request POST --data 'plain=text' https://mydomain /function | X-Body-Error": "CT002" |
curl -H "Content-Type: application/json" --request POST --data '{"my_data": {"abc": {"def": {"g": "xyz","h": false,"e": null}}, "number": 1}' https://mydomain/function | X-Body-Error": "FD001" |
Errors
When the function fails, it adds the error code to a new header, X-Body-Error:
| Error code | Description |
|---|---|
CT001 | The Content-Type header is missing or null |
CT002 | The Content-Type header has a value that the function does not support |
FD001 | The request body is not correctly formatted and the function cannot decode it |
Create the rule
The instance processes nothing until a rule runs it. A Rules Engine for Firewall rule selects the requests that reach the instance, through a Run Function behavior. To create the rule:
In Firewalls, select your firewall, then select the Rules Engine tab.
In Name, enter a name. For example: Run Process Request Data Into Headers.
In the Criteria section, select the domains that run the integration. For example: if Host matches yourdomain.com.
In the Behaviors section, select Run Function, then select the instance by the name you gave it.
The firewall runs the instance on every request to the domains in the criterion.
Bind the firewall to the workload
The binding is on the workload’s deployment, so create a deployment that names both the application and the firewall:
The command prints the id of the new deployment:
Requests to the workload’s domain reach the firewall, and the rule runs the Process Request Data Into Headers instance on each one.