Exempt one query string parameter
Stop one internal rule firing on one named query string argument, and leave it firing everywhere else, from Azion Console, the Azion CLI, or the API.
You can create a WAF exception that stops one internal rule scoring one query string argument from Azion Console, the Azion CLI, or the API. The exception below stops rule 1013, the apostrophe rule, firing on the q argument of /search, and leaves it firing on every other argument, path, and header.
Prerequisites
- The rule set that blocked the request, such as
storefront-waf. - The id of the internal rule that fired. To read it, refer to Read the score of a blocked request.
- The Azion CLI installed and a configured personal token, for the CLI procedure.
- A personal token, for the API request.
Create the exception
To create the exception from Azion Console:
Access Azion Console > Edge Libraries > WAF Rules.
In Rule ID, select 1013.
In Description, enter Allow apostrophes in the storefront search term. In Path, enter /search.
In Condition, select Specific Query String Name and enter q in the Name field it reveals. In Operator, select contains.
Rule 1013 no longer scores the q argument of /search, and keeps scoring every other argument, path, and header.
For the same exception with every field it accepts explained, refer to Create a WAF exception.