Created
August 25, 2026 14:46
-
-
Save rikatz/3268d8ccd73e08962320d62fe4a7ae8f to your computer and use it in GitHub Desktop.
bench coraza
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| func BenchmarkFilterOnHttpRequestHeaders(b *testing.B) { | |
| shouldIntervene := true | |
| shouldLog := true | |
| config := fmt.Sprintf(`{ | |
| "directives_map": { | |
| "rs1": [ | |
| "SecRuleEngine On", | |
| "Include @demo-conf", | |
| "Include @crs-setup-conf", | |
| "SecDebugLogLevel 3", | |
| "Include @owasp_crs/*.conf", | |
| "SecRule REQUEST_URI \"@streq /admin\" \"id:101,phase:1,t:lowercase,deny\" \nSecRule REQUEST_BODY \"@rx maliciouspayload\" \"id:102,phase:2,t:lowercase,deny\" \nSecRule RESPONSE_HEADERS::status \"@rx 406\" \"id:103,phase:3,t:lowercase,deny\" \nSecRule RESPONSE_BODY \"@contains responsebodycode\" \"id:104,phase:4,t:lowercase,deny\"" | |
| ] | |
| }, | |
| "default_directives": "rs1", | |
| "enable_filter_state_logs": true, | |
| "metric_labels": { | |
| "owner": "coraza", | |
| "identifier": "global" | |
| }, | |
| "per_authority_directives":{ | |
| "foo.example.com":"rs1" | |
| }, | |
| "enable_filter_state_logs": %t | |
| }`, shouldLog) | |
| vm := &testVMContext{} | |
| opt := proxytest. | |
| NewEmulatorOption(). | |
| WithVMContext(vm). | |
| WithPluginConfiguration([]byte(config)) | |
| host, reset := proxytest.NewHostEmulator(opt) | |
| defer reset() | |
| // Initialize VM and plugin configuration callbacks | |
| if host.StartVM() != types.OnVMStartStatusOK { | |
| b.Fatal("failed to start VM") | |
| } | |
| if host.StartPlugin() != types.OnPluginStartStatusOK { | |
| b.Fatal("failed to start plugin") | |
| } | |
| // Reset timer to ignore startup/initialization overhead | |
| b.ResetTimer() | |
| reqHeaders := [][2]string{ | |
| {":path", "/api/v1/resource"}, | |
| {":method", "GET"}, | |
| {":authority", "foo.example.com"}, | |
| {"content-type", "application/json"}, | |
| } | |
| reqBody := []byte(`{"username": "john", "bio": "something something nothing something something nothing this can be a very big payload"}`) | |
| if shouldIntervene { | |
| reqBody = []byte(`{"username": "john", "bio": "<script>alert('xxxx');</script>"}`) | |
| } | |
| respHeaders := [][2]string{ | |
| {":status", "200"}, | |
| {"content-type", "text/html"}, | |
| } | |
| respBody := []byte(`<html><body>Profile updated for user</body></html>`) | |
| for i := 0; i < b.N; i++ { | |
| contextID := host.InitializeHttpContext() | |
| // Simulate Envoy passing HTTP headers to your WASM plugin | |
| action := host.CallOnRequestHeaders(contextID, reqHeaders, false) | |
| // With failure_policy=allow, we expect the request to continue despite the error | |
| if action != types.ActionContinue { | |
| b.Fatal("action should be continue") | |
| } | |
| action = host.CallOnRequestBody(contextID, reqBody, true) | |
| if shouldIntervene { | |
| if action != types.ActionPause { | |
| b.Fatal("action should be continue") | |
| } | |
| continue | |
| } | |
| if action != types.ActionContinue { | |
| b.Fatal("action should be continue") | |
| } | |
| action = host.CallOnResponseHeaders(contextID, respHeaders, false) | |
| if action != types.ActionContinue { | |
| b.Fatal("action should be continue") | |
| } | |
| action = host.CallOnResponseBody(contextID, respBody, true) | |
| if action != types.ActionContinue { | |
| b.Fatal("action should be continue") | |
| } | |
| } | |
| } |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment