-
Notifications
You must be signed in to change notification settings - Fork 411
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore(wsgi): remove some appsec code from wsgi contrib #6326
Merged
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
…on a context that still exists by the time the test assertion runs
This reverts commit b47ab26.
explicitly set expected config because config can leak between tests
…atibility with tests that rely on the root span continuing to exist
juanjux
previously approved these changes
Jul 13, 2023
BenchmarksComparing candidate commit 2947218 in PR branch Found 1 performance improvements and 0 performance regressions! Performance is the same for 93 cases. scenario:flasksimple-appsec-get
|
juanjux
approved these changes
Jul 17, 2023
ZStriker19
reviewed
Jul 17, 2023
ZStriker19
reviewed
Jul 17, 2023
ZStriker19
reviewed
Jul 17, 2023
ZStriker19
reviewed
Jul 17, 2023
ZStriker19
approved these changes
Jul 17, 2023
romainkomorndatadog
pushed a commit
that referenced
this pull request
Aug 8, 2023
This change adjusts the `flask_block` callback-setting logic to use the Core API rather than the AppSec-specific `set_value` call it had used previously. In the case of request blocking, the separation of concerns ideally breaks down as follows. The AppSec Product code in the `ddtrace/appsec` directory knows how to make a block/don't block decision based on communication with libddwaf. The Wsgi code in `ddtrace/contrib` knows how to take that blocking decision into account when processing requests. ## Checklist - [x] Change(s) are motivated and described in the PR description. - [x] Testing strategy is described if automated tests are not included in the PR. - [x] Risk is outlined (performance impact, potential for breakage, maintainability, etc). - [x] Change is maintainable (easy to change, telemetry, documentation). - [x] [Library release note guidelines](https://ddtrace.readthedocs.io/en/stable/releasenotes.html) are followed. If no release note is required, add label `changelog/no-changelog`. - [x] Documentation is included (in-code, generated user docs, [public corp docs](https://github.com/DataDog/documentation/)). - [x] Backport labels are set (if [applicable](https://ddtrace.readthedocs.io/en/latest/contributing.html#backporting)) ## Reviewer Checklist - [ ] Title is accurate. - [ ] No unnecessary changes are introduced. - [ ] Description motivates each change. - [ ] Avoids breaking [API](https://ddtrace.readthedocs.io/en/stable/versioning.html#interfaces) changes unless absolutely necessary. - [ ] Testing strategy adequately addresses listed risk(s). - [ ] Change is maintainable (easy to change, telemetry, documentation). - [ ] Release note makes sense to a user of the library. - [ ] Reviewer has explicitly acknowledged and discussed the performance implications of this PR as reported in the benchmarks PR comment. - [ ] Backport labels are set in a manner that is consistent with the [release branch maintenance policy](https://ddtrace.readthedocs.io/en/latest/contributing.html#backporting) --------- Co-authored-by: Federico Mon <federico.mon@datadoghq.com>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
ASM
Application Security Monitoring
changelog/no-changelog
A changelog entry is not required for this PR.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This change adjusts the
flask_block
callback-setting logic to use the Core API rather than the AppSec-specificset_value
call it had used previously.In the case of request blocking, the separation of concerns ideally breaks down as follows. The AppSec Product code in the
ddtrace/appsec
directory knows how to make a block/don't block decision based on communication with libddwaf. The Wsgi code inddtrace/contrib
knows how to take that blocking decision into account when processing requests.Checklist
changelog/no-changelog
.Reviewer Checklist