Skip to content

Instantly share code, notes, and snippets.

@rikatz
Created August 25, 2026 14:46
Show Gist options
  • Select an option

  • Save rikatz/3268d8ccd73e08962320d62fe4a7ae8f to your computer and use it in GitHub Desktop.

Select an option

Save rikatz/3268d8ccd73e08962320d62fe4a7ae8f to your computer and use it in GitHub Desktop.
bench coraza
func BenchmarkFilterOnHttpRequestHeaders(b *testing.B) {
shouldIntervene := true
shouldLog := true
config := fmt.Sprintf(`{
"directives_map": {
"rs1": [
"SecRuleEngine On",
"Include @demo-conf",
"Include @crs-setup-conf",
"SecDebugLogLevel 3",
"Include @owasp_crs/*.conf",
"SecRule REQUEST_URI \"@streq /admin\" \"id:101,phase:1,t:lowercase,deny\" \nSecRule REQUEST_BODY \"@rx maliciouspayload\" \"id:102,phase:2,t:lowercase,deny\" \nSecRule RESPONSE_HEADERS::status \"@rx 406\" \"id:103,phase:3,t:lowercase,deny\" \nSecRule RESPONSE_BODY \"@contains responsebodycode\" \"id:104,phase:4,t:lowercase,deny\""
]
},
"default_directives": "rs1",
"enable_filter_state_logs": true,
"metric_labels": {
"owner": "coraza",
"identifier": "global"
},
"per_authority_directives":{
"foo.example.com":"rs1"
},
"enable_filter_state_logs": %t
}`, shouldLog)
vm := &testVMContext{}
opt := proxytest.
NewEmulatorOption().
WithVMContext(vm).
WithPluginConfiguration([]byte(config))
host, reset := proxytest.NewHostEmulator(opt)
defer reset()
// Initialize VM and plugin configuration callbacks
if host.StartVM() != types.OnVMStartStatusOK {
b.Fatal("failed to start VM")
}
if host.StartPlugin() != types.OnPluginStartStatusOK {
b.Fatal("failed to start plugin")
}
// Reset timer to ignore startup/initialization overhead
b.ResetTimer()
reqHeaders := [][2]string{
{":path", "/api/v1/resource"},
{":method", "GET"},
{":authority", "foo.example.com"},
{"content-type", "application/json"},
}
reqBody := []byte(`{"username": "john", "bio": "something something nothing something something nothing this can be a very big payload"}`)
if shouldIntervene {
reqBody = []byte(`{"username": "john", "bio": "<script>alert('xxxx');</script>"}`)
}
respHeaders := [][2]string{
{":status", "200"},
{"content-type", "text/html"},
}
respBody := []byte(`<html><body>Profile updated for user</body></html>`)
for i := 0; i < b.N; i++ {
contextID := host.InitializeHttpContext()
// Simulate Envoy passing HTTP headers to your WASM plugin
action := host.CallOnRequestHeaders(contextID, reqHeaders, false)
// With failure_policy=allow, we expect the request to continue despite the error
if action != types.ActionContinue {
b.Fatal("action should be continue")
}
action = host.CallOnRequestBody(contextID, reqBody, true)
if shouldIntervene {
if action != types.ActionPause {
b.Fatal("action should be continue")
}
continue
}
if action != types.ActionContinue {
b.Fatal("action should be continue")
}
action = host.CallOnResponseHeaders(contextID, respHeaders, false)
if action != types.ActionContinue {
b.Fatal("action should be continue")
}
action = host.CallOnResponseBody(contextID, respBody, true)
if action != types.ActionContinue {
b.Fatal("action should be continue")
}
}
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment