import os
from gcore import Gcore
client = Gcore(
api_key=os.environ.get("GCORE_API_KEY"), # This is the default and can be omitted
)
waap_advanced_rule = client.waap.domains.advanced_rules.create(
domain_id=1,
action={},
enabled=True,
name="Block foobar bot",
source="request.rate_limit([], '.*events', 5, 200, [], [], '', 'ip') and not ('mb-web-ui' in request.headers['Cookie'] or 'mb-mobile-ios' in request.headers['Cookie'] or 'session-token' in request.headers['Cookie']) and not request.headers['session']",
)
print(waap_advanced_rule.id)package main
import (
"context"
"fmt"
"github.com/G-Core/gcore-go"
"github.com/G-Core/gcore-go/option"
"github.com/G-Core/gcore-go/waap"
)
func main() {
client := gcore.NewClient(
option.WithAPIKey("My API Key"),
)
waapAdvancedRule, err := client.Waap.Domains.AdvancedRules.New(
context.TODO(),
1,
waap.DomainAdvancedRuleNewParams{
Action: waap.DomainAdvancedRuleNewParamsAction{},
Enabled: true,
Name: "Block foobar bot",
Source: "request.rate_limit([], '.*events', 5, 200, [], [], '', 'ip') and not ('mb-web-ui' in request.headers['Cookie'] or 'mb-mobile-ios' in request.headers['Cookie'] or 'session-token' in request.headers['Cookie']) and not request.headers['session']",
},
)
if err != nil {
panic(err.Error())
}
fmt.Printf("%+v\n", waapAdvancedRule.ID)
}
curl --request POST \
--url https://api.gcore.com/waap/v1/domains/{domain_id}/advanced-rules \
--header 'Authorization: <api-key>' \
--header 'Content-Type: application/json' \
--data @- <<EOF
{
"name": "Block foobar bot",
"enabled": true,
"action": {
"allow": {},
"block": {
"action_duration": "12h"
},
"captcha": {},
"handshake": {},
"monitor": {}
},
"source": "request.rate_limit([], '.*events', 5, 200, [], [], '', 'ip') and not ('mb-web-ui' in request.headers['Cookie'] or 'mb-mobile-ios' in request.headers['Cookie'] or 'session-token' in request.headers['Cookie']) and not request.headers['session']",
"description": "<string>",
"phase": "access"
}
EOFconst options = {
method: 'POST',
headers: {Authorization: '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: 'Block foobar bot',
enabled: true,
action: {
allow: {},
block: {action_duration: '12h'},
captcha: {},
handshake: {},
monitor: {}
},
source: 'request.rate_limit([], \'.*events\', 5, 200, [], [], \'\', \'ip\') and not (\'mb-web-ui\' in request.headers[\'Cookie\'] or \'mb-mobile-ios\' in request.headers[\'Cookie\'] or \'session-token\' in request.headers[\'Cookie\']) and not request.headers[\'session\']',
description: '<string>',
phase: 'access'
})
};
fetch('https://api.gcore.com/waap/v1/domains/{domain_id}/advanced-rules', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.gcore.com/waap/v1/domains/{domain_id}/advanced-rules",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => 'Block foobar bot',
'enabled' => true,
'action' => [
'allow' => [
],
'block' => [
'action_duration' => '12h'
],
'captcha' => [
],
'handshake' => [
],
'monitor' => [
]
],
'source' => 'request.rate_limit([], \'.*events\', 5, 200, [], [], \'\', \'ip\') and not (\'mb-web-ui\' in request.headers[\'Cookie\'] or \'mb-mobile-ios\' in request.headers[\'Cookie\'] or \'session-token\' in request.headers[\'Cookie\']) and not request.headers[\'session\']',
'description' => '<string>',
'phase' => 'access'
]),
CURLOPT_HTTPHEADER => [
"Authorization: <api-key>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}HttpResponse<String> response = Unirest.post("https://api.gcore.com/waap/v1/domains/{domain_id}/advanced-rules")
.header("Authorization", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"Block foobar bot\",\n \"enabled\": true,\n \"action\": {\n \"allow\": {},\n \"block\": {\n \"action_duration\": \"12h\"\n },\n \"captcha\": {},\n \"handshake\": {},\n \"monitor\": {}\n },\n \"source\": \"request.rate_limit([], '.*events', 5, 200, [], [], '', 'ip') and not ('mb-web-ui' in request.headers['Cookie'] or 'mb-mobile-ios' in request.headers['Cookie'] or 'session-token' in request.headers['Cookie']) and not request.headers['session']\",\n \"description\": \"<string>\",\n \"phase\": \"access\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.gcore.com/waap/v1/domains/{domain_id}/advanced-rules")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"Block foobar bot\",\n \"enabled\": true,\n \"action\": {\n \"allow\": {},\n \"block\": {\n \"action_duration\": \"12h\"\n },\n \"captcha\": {},\n \"handshake\": {},\n \"monitor\": {}\n },\n \"source\": \"request.rate_limit([], '.*events', 5, 200, [], [], '', 'ip') and not ('mb-web-ui' in request.headers['Cookie'] or 'mb-mobile-ios' in request.headers['Cookie'] or 'session-token' in request.headers['Cookie']) and not request.headers['session']\",\n \"description\": \"<string>\",\n \"phase\": \"access\"\n}"
response = http.request(request)
puts response.read_body{
"name": "Block foobar bot",
"enabled": true,
"action": {
"allow": {},
"block": {
"status_code": 403,
"action_duration": "12h"
},
"captcha": {},
"handshake": {},
"monitor": {},
"tag": {
"tags": [
"<string>"
]
}
},
"source": "request.rate_limit([], '.*events', 5, 200, [], [], '', 'ip') and not ('mb-web-ui' in request.headers['Cookie'] or 'mb-mobile-ios' in request.headers['Cookie'] or 'session-token' in request.headers['Cookie']) and not request.headers['session']",
"id": 123,
"description": "<string>",
"phase": "access"
}{
"type": "http-bad-request",
"title": "Bad Request",
"status": 400,
"detail": "Invalid domain name: ''''"
}{
"detail": "Auth token is missing or invalid"
}{
"title": "Quota limit exceeded",
"type": "quota-check-limit-exceeded",
"status": 403,
"detail": "You have reached the maximum limit allowed for your current plan. Please upgrade your plan to add more."
}{
"title": "Resource not found",
"type": "quota-check-no-resource",
"status": 404,
"detail": "The quota resource requested does not exist. Cannot enable WAAP for this domain. Please reach out to our support team."
}{
"type": "request-validation-failed",
"title": "Request validation error.",
"status": 422,
"detail": "One or more fields have validation errors.",
"errors": [
{
"loc": [
"body",
"name"
],
"detail": "Input should be a valid string"
},
{
"loc": [
"body",
"date"
],
"detail": "Field required"
},
{
"loc": [
"query",
"limit"
],
"detail": "Field required"
}
]
}{
"type": "internal-server-error",
"title": "Internal server error.",
"status": 500,
"detail": "An unexpected condition was encountered which prevented the server from fulfilling the request."
}Create an advanced rule
import os
from gcore import Gcore
client = Gcore(
api_key=os.environ.get("GCORE_API_KEY"), # This is the default and can be omitted
)
waap_advanced_rule = client.waap.domains.advanced_rules.create(
domain_id=1,
action={},
enabled=True,
name="Block foobar bot",
source="request.rate_limit([], '.*events', 5, 200, [], [], '', 'ip') and not ('mb-web-ui' in request.headers['Cookie'] or 'mb-mobile-ios' in request.headers['Cookie'] or 'session-token' in request.headers['Cookie']) and not request.headers['session']",
)
print(waap_advanced_rule.id)package main
import (
"context"
"fmt"
"github.com/G-Core/gcore-go"
"github.com/G-Core/gcore-go/option"
"github.com/G-Core/gcore-go/waap"
)
func main() {
client := gcore.NewClient(
option.WithAPIKey("My API Key"),
)
waapAdvancedRule, err := client.Waap.Domains.AdvancedRules.New(
context.TODO(),
1,
waap.DomainAdvancedRuleNewParams{
Action: waap.DomainAdvancedRuleNewParamsAction{},
Enabled: true,
Name: "Block foobar bot",
Source: "request.rate_limit([], '.*events', 5, 200, [], [], '', 'ip') and not ('mb-web-ui' in request.headers['Cookie'] or 'mb-mobile-ios' in request.headers['Cookie'] or 'session-token' in request.headers['Cookie']) and not request.headers['session']",
},
)
if err != nil {
panic(err.Error())
}
fmt.Printf("%+v\n", waapAdvancedRule.ID)
}
curl --request POST \
--url https://api.gcore.com/waap/v1/domains/{domain_id}/advanced-rules \
--header 'Authorization: <api-key>' \
--header 'Content-Type: application/json' \
--data @- <<EOF
{
"name": "Block foobar bot",
"enabled": true,
"action": {
"allow": {},
"block": {
"action_duration": "12h"
},
"captcha": {},
"handshake": {},
"monitor": {}
},
"source": "request.rate_limit([], '.*events', 5, 200, [], [], '', 'ip') and not ('mb-web-ui' in request.headers['Cookie'] or 'mb-mobile-ios' in request.headers['Cookie'] or 'session-token' in request.headers['Cookie']) and not request.headers['session']",
"description": "<string>",
"phase": "access"
}
EOFconst options = {
method: 'POST',
headers: {Authorization: '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: 'Block foobar bot',
enabled: true,
action: {
allow: {},
block: {action_duration: '12h'},
captcha: {},
handshake: {},
monitor: {}
},
source: 'request.rate_limit([], \'.*events\', 5, 200, [], [], \'\', \'ip\') and not (\'mb-web-ui\' in request.headers[\'Cookie\'] or \'mb-mobile-ios\' in request.headers[\'Cookie\'] or \'session-token\' in request.headers[\'Cookie\']) and not request.headers[\'session\']',
description: '<string>',
phase: 'access'
})
};
fetch('https://api.gcore.com/waap/v1/domains/{domain_id}/advanced-rules', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.gcore.com/waap/v1/domains/{domain_id}/advanced-rules",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => 'Block foobar bot',
'enabled' => true,
'action' => [
'allow' => [
],
'block' => [
'action_duration' => '12h'
],
'captcha' => [
],
'handshake' => [
],
'monitor' => [
]
],
'source' => 'request.rate_limit([], \'.*events\', 5, 200, [], [], \'\', \'ip\') and not (\'mb-web-ui\' in request.headers[\'Cookie\'] or \'mb-mobile-ios\' in request.headers[\'Cookie\'] or \'session-token\' in request.headers[\'Cookie\']) and not request.headers[\'session\']',
'description' => '<string>',
'phase' => 'access'
]),
CURLOPT_HTTPHEADER => [
"Authorization: <api-key>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}HttpResponse<String> response = Unirest.post("https://api.gcore.com/waap/v1/domains/{domain_id}/advanced-rules")
.header("Authorization", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"Block foobar bot\",\n \"enabled\": true,\n \"action\": {\n \"allow\": {},\n \"block\": {\n \"action_duration\": \"12h\"\n },\n \"captcha\": {},\n \"handshake\": {},\n \"monitor\": {}\n },\n \"source\": \"request.rate_limit([], '.*events', 5, 200, [], [], '', 'ip') and not ('mb-web-ui' in request.headers['Cookie'] or 'mb-mobile-ios' in request.headers['Cookie'] or 'session-token' in request.headers['Cookie']) and not request.headers['session']\",\n \"description\": \"<string>\",\n \"phase\": \"access\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.gcore.com/waap/v1/domains/{domain_id}/advanced-rules")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"Block foobar bot\",\n \"enabled\": true,\n \"action\": {\n \"allow\": {},\n \"block\": {\n \"action_duration\": \"12h\"\n },\n \"captcha\": {},\n \"handshake\": {},\n \"monitor\": {}\n },\n \"source\": \"request.rate_limit([], '.*events', 5, 200, [], [], '', 'ip') and not ('mb-web-ui' in request.headers['Cookie'] or 'mb-mobile-ios' in request.headers['Cookie'] or 'session-token' in request.headers['Cookie']) and not request.headers['session']\",\n \"description\": \"<string>\",\n \"phase\": \"access\"\n}"
response = http.request(request)
puts response.read_body{
"name": "Block foobar bot",
"enabled": true,
"action": {
"allow": {},
"block": {
"status_code": 403,
"action_duration": "12h"
},
"captcha": {},
"handshake": {},
"monitor": {},
"tag": {
"tags": [
"<string>"
]
}
},
"source": "request.rate_limit([], '.*events', 5, 200, [], [], '', 'ip') and not ('mb-web-ui' in request.headers['Cookie'] or 'mb-mobile-ios' in request.headers['Cookie'] or 'session-token' in request.headers['Cookie']) and not request.headers['session']",
"id": 123,
"description": "<string>",
"phase": "access"
}{
"type": "http-bad-request",
"title": "Bad Request",
"status": 400,
"detail": "Invalid domain name: ''''"
}{
"detail": "Auth token is missing or invalid"
}{
"title": "Quota limit exceeded",
"type": "quota-check-limit-exceeded",
"status": 403,
"detail": "You have reached the maximum limit allowed for your current plan. Please upgrade your plan to add more."
}{
"title": "Resource not found",
"type": "quota-check-no-resource",
"status": 404,
"detail": "The quota resource requested does not exist. Cannot enable WAAP for this domain. Please reach out to our support team."
}{
"type": "request-validation-failed",
"title": "Request validation error.",
"status": 422,
"detail": "One or more fields have validation errors.",
"errors": [
{
"loc": [
"body",
"name"
],
"detail": "Input should be a valid string"
},
{
"loc": [
"body",
"date"
],
"detail": "Field required"
},
{
"loc": [
"query",
"limit"
],
"detail": "Field required"
}
]
}{
"type": "internal-server-error",
"title": "Internal server error.",
"status": 500,
"detail": "An unexpected condition was encountered which prevented the server from fulfilling the request."
}Authorizations
API key for authentication. Make sure to include the word apikey, followed by a single space and then your token.
Example: apikey 1234_abcdef
Path Parameters
The domain ID
Body
A request to create a new advanced rule
The name assigned to the rule
1 - 100^[A-Za-z0-9\s.:'";<>?&|\\]+$"Block foobar bot"
Whether or not the rule is enabled
The action that the rule takes when triggered. Only one action can be set per rule.
Show child attributes
Show child attributes
A CEL syntax expression that contains the rule's conditions. Allowed objects are: request, whois, session, response, tags, user_defined_tags, user_agent, client_data.
More info can be found here: https://gcore.com/docs/waap/waap-rules/advanced-rules
1"request.rate_limit([], '.*events', 5, 200, [], [], '', 'ip') and not ('mb-web-ui' in request.headers['Cookie'] or 'mb-mobile-ios' in request.headers['Cookie'] or 'session-token' in request.headers['Cookie']) and not request.headers['session']"
The description assigned to the rule
100The WAAP request/response phase for applying the rule. Default is "access".
The "access" phase is responsible for modifying the request before it is sent to the origin server.
The "header_filter" phase is responsible for modifying the HTTP headers of a response before they are sent back to the client.
The "body_filter" phase is responsible for modifying the body of a response before it is sent back to the client.
access, header_filter, body_filter Response
Successful Response
An advanced WAAP rule applied to a domain
The name assigned to the rule
1 - 100^[A-Za-z0-9\s.:'";<>?&|\\]+$"Block foobar bot"
Whether or not the rule is enabled
The action that the rule takes when triggered. Only one action can be set per rule.
Show child attributes
Show child attributes
A CEL syntax expression that contains the rule's conditions. Allowed objects are: request, whois, session, response, tags, user_defined_tags, user_agent, client_data.
More info can be found here: https://gcore.com/docs/waap/waap-rules/advanced-rules
1"request.rate_limit([], '.*events', 5, 200, [], [], '', 'ip') and not ('mb-web-ui' in request.headers['Cookie'] or 'mb-mobile-ios' in request.headers['Cookie'] or 'session-token' in request.headers['Cookie']) and not request.headers['session']"
The unique identifier for the rule
The description assigned to the rule
100The WAAP request/response phase for applying the rule. Default is "access".
The "access" phase is responsible for modifying the request before it is sent to the origin server.
The "header_filter" phase is responsible for modifying the HTTP headers of a response before they are sent back to the client.
The "body_filter" phase is responsible for modifying the body of a response before it is sent back to the client.
access, header_filter, body_filter Was this page helpful?