---
name: azion-install-the-request-variation-controller-integration
description: >-
  Install the Request Variation Controller from Azion Marketplace and run it on an application to count how often a user changes request arguments.
---

# Install the Request Variation Controller integration

Request Variation Controller counts how many different requests a user makes in succession to an application, and flags the user who exceeds the maximum you allow. It is two integrations that run on the same application, and both are among the [Marketplace integrations](/en/documentation/platform/marketplace/integrations/). In the response phase, the **Hash Generator** creates or updates a signed cookie that tracks the arguments the user, or the origin, sends across requests. In the request phase, the **Hash Validator** reads that cookie, checks the number of variations, and marks the request when the user exceeds the maximum.

Seven objects must exist before a request is checked: the two installed functions, an application with the **Functions** and **Application Accelerator** modules turned on, one function instance per integration, and one Rules Engine rule per instance.

---

## Prerequisites

- An Azion account. To sign in, refer to [How to access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).
- An [application](/en/documentation/platform/applications/) served by a [workload](/en/documentation/platform/workloads/). To create one, refer to [Applications quickstart](/en/documentation/platform/applications/quickstart/).
- Turning on a product or a module can generate usage costs. For more information, refer to [Pricing](/en/documentation/fundamentals/pricing/).

---

## Install the integrations

Each install adds one function to your account. To install both from Azion Console:

1. **Open Marketplace**

   Access [Azion Console](https://console.azion.com/) > **Marketplace**.

2. **Find the Hash Generator**

   Enter `variation` in the **Search on Marketplace** field, then select the **Request Variation Controller - Hash Generator** card. Browsing the cards reaches the same page.

3. **Select Install**

4. **Install the Hash Validator**

   Return to **Marketplace**, select the **Request Variation Controller - Hash Validator** card, then select **Install**.

Each card shows `Successfully installed!` and `Latest version installed!`, and both functions appear in the **Function** list of the **Create Instance** drawer.

---

## Turn on the Functions module

An application runs an installed function only when its **Functions** module is on. The rule that runs the Hash Validator also uses the **Forward Cookies** behavior, which requires the **Application Accelerator** module. To turn on both modules:

1. **Open your application**

   Access [Azion Console](https://console.azion.com/) > **Applications** > **your application**.

2. **Open the Modules section**

   In the **Main Settings** tab, go to the **Modules** section.

3. **Turn on the Functions switch**

4. **Turn on the Application Accelerator switch**

5. **Select Save**

Azion Console confirms that the application was updated.

---

## Create the function instances

Each integration needs its own function instance with its own arguments. The Hash Generator runs in the response phase and the Hash Validator in the request phase. To create the two instances in your application:

1. **Open the Functions Instances tab**

   In **Applications**, select your application, then select the **Functions Instances** tab.

2. **Select + Function**

   An application with no instance yet offers the same action as **Function Instance**. The **Create Instance** drawer opens.

3. **Name the instance**

   In **Name**, enter a unique name that identifies the instance. For example: `variation-generator`.

4. **Select the function**

   In **Function**, select the *Variation Request - Hash Generator* function. The **Arguments** editor fills with the default arguments of the integration.

5. **Edit the arguments**

   In **Arguments**, enter the Hash Generator arguments described below.

6. **Select Save**

7. **Create the Hash Validator instance**

   Repeat these steps with a name such as `variation-validator`, the *Variation Request - Hash Validator* function, and the Hash Validator arguments.

Both instances appear in the **Functions Instances** tab with the names you entered.

### Hash Generator arguments

The Hash Generator runs in the response phase and takes these arguments:

```json
{
    "cookie_name": "azn",
    "cookie_secret": "1234567890123456",
    "cookie_max_age": 45,
    "args_list": ["http_x_something", "http_x_another_thing",
    "request_body_userid"]
}
```

| Key              | Description                                                                                                                                                |
| ---------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `cookie_name`    | The name of the cookie. The default value is `azn`                                                                                                         |
| `cookie_secret`  | The key that encrypts the signed cookie. The encryption algorithm is AES-128, so the key must have exactly 16 characters                                   |
| `cookie_max_age` | The time until the cookie expires. Without a value, `null` or none, the cookie is a session cookie. The default value is `45`                              |
| `args_list`      | The nginx variables analyzed on the user's request. Each change increases the count of changes, and the count decides whether access is blocked or allowed |

### Hash Validator arguments

The Hash Validator runs in the request phase and takes these arguments:

```json
{
"cookie_name": "azn",
"cookie_secret": "1234567890123456",
"max_variation": 6,
"max_unique_variation": 2
}
```

| Key                    | Description                                                                          |
| ---------------------- | ------------------------------------------------------------------------------------ |
| `cookie_name`          | The name of the cookie. It must be the same as in the Hash Generator arguments       |
| `cookie_secret`        | The secret key of the cookie. It must be the same as in the Hash Generator arguments |
| `max_variation`        | The maximum number of variations of any kind in the parameters                       |
| `max_unique_variation` | The maximum number of unique variations in the parameters                            |

The Hash Validator decrypts the signed cookie and checks whether a variation limit was reached. If it was, the function appends a request header named `[COOKIE_ NAME]-[VIOLATION TYPE]-[TRUE]`.

### Violation types

A violation takes one of three types. The examples use a cookie that changes from no value to `A` in the first request, `A` to `B` in the second, `C` in the third, `B` to `C` in the fourth, `B` to `A` in the fifth, and `A` in the sixth.

- **All variations**: counts every time the cookie value changed, repeated values included. The example has 5 variations. With the default cookie name, the violation adds the `http_cookie_name_any_variation_violation` header to the request.
- **Unique variations**: counts the distinct values assigned to the cookie since it was created. The example has 3, because the cookie held only `A`, `B`, and `C`. With the default cookie name, the violation adds the `http_cookie_name_unique_variation_violation` header to the request.
- **Signature violation**: occurs when the function cannot decrypt the signed cookie, because it was signed with a different key or altered on the client side. With the default cookie name, the violation adds the `http_cookie_name_signature_violation` header to the request.

---

## Create the rules

Each instance runs only when a Rules Engine rule calls it. The Hash Generator rule runs in the response phase. The Hash Validator rule runs in the request phase and adds the **Forward Cookies** behavior, which requires the **Application Accelerator** module. Both rules below match every request. To create the rules:

1. **Open the Rules Engine tab**

   In **Applications**, select your application, then select the **Rules Engine** tab.

2. **Select + Rule**

3. **Name the Hash Generator rule**

   In **Name**, enter a name for the rule. For example: `Track request variations`. A **Description** is optional.

4. **Select the response phase**

   In the **Phase** section, select *Response Phase*.

5. **Set the criterion**

   In the **Criteria** section, keep the `${uri}` variable and the *starts with* operator, then enter `/` as the argument.

6. **Add the Run Function behavior**

   In the **Behaviors** section, select *Run Function*, then select the Hash Generator instance by its name.

7. **Select Save**

8. **Create the Hash Validator rule**

   Select **+ Rule** again. Enter a name, select *Request Phase*, and set the same criterion.

9. **Add the Run Function behavior**

   In the **Behaviors** section, select *Run Function*, then select the Hash Validator instance by its name.

10. **Add the Forward Cookies behavior**

    Select **Add Behavior**, then select *Forward Cookies*.

11. **Select Save**

The **Rules Engine** tab lists one rule under the response phase and one under the request phase. A request that exceeds a variation limit reaches your application with the violation header.

For every criterion and behavior a rule accepts, refer to [Rules Engine](/en/documentation/platform/applications/rules-engine/).

---

## Next steps

- [Marketplace integrations](/en/documentation/platform/marketplace/integrations.md): The integrations Marketplace offers, and the application or firewall each one runs on.
- [Rules Engine](/en/documentation/platform/applications/rules-engine.md): The criteria and behaviors a rule accepts, including Run Function and Forward Cookies.
- [Install the Signed Cookies integration](/en/documentation/guides/application-development/integrations/signed-cookies.md): How to detect cookies altered on the client side with a hash generator and a hash validator.
- [Update an integration](/en/documentation/guides/application-development/integrations/update-an-integration.md): How to get the latest version of an installed integration, and what an update creates.
