Deny a request by country
Block requests from a chosen country before they reach your application, with a function that runs on a firewall.
Deny or allow a request based on the visitor’s country, resolved from GeoIP data on Azion’s global network. Use this pattern in a firewall function to enforce geographic restrictions, blocking traffic from specific regions before it ever reaches your application.
How it works
This code runs as a firewall handler, so it executes in a firewall before the request reaches an application. It registers the handler with addEventListener("firewall", ...) and runs the asynchronous work inside event.waitUntil(). Refer to Functions for Firewall for the full set of actions a firewall handler can call.
The handler reads the visitor’s country from event.request.metadata["geoip_country_code"]. When the request comes from Brazil it calls event.deny(), which returns a default 403 response and stops further processing. For requests from any other country, event.continue() allows the request to proceed to its destination.