Exempt one request header
Name a single header in a WAF exception from the API, and avoid the condition shape that silently covers every header.
You can create a WAF exception that names a single request header from the API. The exception below stops rule 1005, the pipe-character rule, firing on the Cookie header, and leaves it firing on the body, the path, and the query string.
Prerequisites
- The rule set that blocked the request, such as
storefront-waf. - A personal token.
Create the exception
Send a POST request to the rule set’s exceptions endpoint, with specific_http_header_name as the match value:
The API answers 202 and echoes the exception under data, with the name key of the condition intact. The Azion CLI sends the same body from a file with azion create waf-exceptions --waf-id <waf-id> --file exception.json.
For the key each of the fifteen match values carries, refer to WAF Exceptions.