Re: Add Headers with NGinx and ModSecurity

Mikaël Pirio <[email protected]>
Newsgroups gmane.comp.apache.mod-security.user
Message-ID <CAG1WCxiVULHkGic54j5eCuHMXzEEVqPtSb8mf8DNNV7QTHbGBQ@mail.gmail.com>
Really ? We can't add a custom response header in Nginx if an env variable
is set in ModSec?  Like in the example with Apache:

# In ModSec rules file, define 'ratelimit_limit' env variable
SecRule &TX:IS_API_REQ "@eq 1"
"id:'129793',phase:2,setenv:'ratelimit_limit=%{tx.api_req_counter_max}'"

# In Apache conf, use mod_header to set Header based on that env variable
Header always set X-RateLimit-Limit "%{ratelimit_limit}e"

Le jeu. 17 sept. 2020 à 19:51, Christian Folini <[email protected]>
a écrit :

>
> Unfortunately not. NGINX does not even let ModSec inspect the response,
> let alone manipulate it. It's an architecture decision with the webserver.
>
> Christian
>

_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.