---
name: azion-exempt-one-query-string-parameter
description: >-
  Stop one internal rule firing on one named query string argument, and leave it firing everywhere else, from Azion Console, the Azion CLI, or the API.
---

# Exempt one query string parameter

You can create a WAF exception that stops one internal rule scoring one query string argument from Azion Console, the Azion CLI, or the API. The exception below stops rule `1013`, the apostrophe rule, firing on the `q` argument of `/search`, and leaves it firing on every other argument, path, and header.

---

## Prerequisites

- The rule set that blocked the request, such as `storefront-waf`.
- The id of the internal rule that fired. To read it, refer to [Read the score of a blocked request](/en/documentation/guides/application-security/firewall-and-waf/read-block-score/).
- The [Azion CLI](/en/documentation/devtools/cli/) installed and a configured personal token, for the CLI procedure.
- A personal token, for the API request.

---

## Create the exception

**Console**

To create the exception from Azion Console:

1. **Open the WAF Rules page**

   Access [Azion Console](https://console.azion.com/) > **Edge Libraries** > **WAF Rules**.

2. **Select the rule set that blocked the request**

3. **Open the Allowed Rules tab and select + Allowed Rule**

4. **Select the rule to exempt**

   In **Rule ID**, select `1013`.

5. **Describe the exception and restrict it to one path**

   In **Description**, enter `Allow apostrophes in the storefront search term`. In **Path**, enter `/search`.

6. **Name the part of the request**

   In **Condition**, select *Specific Query String Name* and enter `q` in the **Name** field it reveals. In **Operator**, select `contains`.

7. **Save the exception**

Rule `1013` no longer scores the `q` argument of `/search`, and keeps scoring every other argument, path, and header.

For the same exception with every field it accepts explained, refer to [Create a WAF exception](/en/documentation/guides/application-security/firewall-and-waf/configure-waf-allowed-rules/).

**CLI**

To create the exception with the Azion CLI, save it as `exception.json`:

```json
{
  "rule_id": 1013,
  "name": "Allow apostrophes in the storefront search term",
  "path": "/search",
  "operator": "contains",
  "active": true,
  "conditions": [
    { "match": "specific_query_string_name", "name": "q" }
  ]
}
```

Then create the exception from the file:

```bash
azion create waf-exceptions --waf-id <waf-id> --file exception.json
```

```text
Created WAF Exception with ID 123464
```

The output reports the id of the new exception.

Pass the body with `--file`. On Azion CLI 4.23.0 the `--conditions` flag never reaches the request: whatever value you pass, the command sends an empty array and the API refuses it with `10049 Min Length List Field` pointing at `/data/conditions`.

**API**

Save the exception as `exception.json`:

```json
{
  "rule_id": 1013,
  "name": "Allow apostrophes in the storefront search term",
  "path": "/search",
  "operator": "contains",
  "active": true,
  "conditions": [
    { "match": "specific_query_string_name", "name": "q" }
  ]
}
```

Send a `POST` request to the rule set's exceptions endpoint, with the file as the body:

```bash
curl --request POST \
  --url https://api.azion.com/v4/workspace/wafs/<waf-id>/exceptions \
  --header 'Accept: application/json' \
  --header 'Authorization: Token [TOKEN VALUE]' \
  --header 'Content-Type: application/json' \
  --data @exception.json
```

The API answers `202` and echoes the condition under `data.conditions`, unchanged.

> **Note**
>
> `specific_query_string_name` names one argument, so the condition takes a `name`; `any_query_string_name` takes `match` alone and covers every argument in the request. Two keys default wider than a false positive usually needs: `rule_id` defaults to `0`, which is every internal rule, and `operator` defaults to `contains`, which treats `name` as a substring rather than a pattern.

---

## Next steps

- [Exempt one request header](/en/documentation/guides/application-security/firewall-and-waf/exempt-request-header.md): The same shape for a header, and the condition that silently covers all of them.
- [WAF Exceptions](/en/documentation/platform/firewall/waf/custom-allowed-rules.md): Every field an exception carries, and the fifteen match values a condition takes.
