How to let certain requests through if they have X-foo header set?
I have a high security mode enabled on my website, however, on this subdomain i'm also hosting a service - seq, which is an analytics / logging app. i want the client to be able to send data to this endpoint without getting interrupted of flagged by cloudflare ddos protection. if the request.http.header has
X-Seq-ApiKey
set to any value (or a custom one if possible?)19 Replies
also the media type is
application/vnd.serilog.clef
wdym cors? its not made from the browsers, its made from a backend service, .NET app running and using serilog to log the stuff to seq
how do i configure this rule to read the header value and then allow the request through though?
cloudflares high security
and anti bot protections
i have default bot protections, and yes i have UAM on
i want to have it on*
but i want this request, which has only one header, which is the X-Seq-ApiKey
set,
well UAM blocks the request ig?, without it logging worksdata:image/s3,"s3://crabby-images/754f6/754f689501f67f43ff58a6e83ce6b545e32ad3be" alt="No description"
expression:
(http.request.full_uri wildcard "https://seq.mydomain.dev/api/events/raw" and http.request.method eq "POST")
data:image/s3,"s3://crabby-images/368e4/368e4a5a4323d97891aae9dd18e8bf48d7f2a93d" alt="No description"
data:image/s3,"s3://crabby-images/2fdfe/2fdfe25ae75817e93c24aa710eb8e584fbe5e49c" alt="No description"
ahh
thanks
that might just be what i needed
data:image/s3,"s3://crabby-images/8f10d/8f10d7f74232668c59768e5abf0fcad2ea97a13f" alt="No description"
how should i use the custom rules?
i mean its just info right? nvm
mb
its still not responding for some reason, maybe the rule isnt good?
data:image/s3,"s3://crabby-images/a58db/a58db1bcc6bcd4e73ec1ffc837ea077dca848f44" alt="No description"
data:image/s3,"s3://crabby-images/dcde6/dcde6ec39eb3d3cdf23382e441f52f203a0d638f" alt="No description"
data:image/s3,"s3://crabby-images/0229d/0229de3b0a4bc66fbf2f0a846d8aea65bcf41a73" alt="No description"
@Leo
data:image/s3,"s3://crabby-images/8b57b/8b57b543d0cc1d8c69651b189883b1a6e9ed10cf" alt="No description"
trace does not seem to be hitting the rule...
data:image/s3,"s3://crabby-images/1812c/1812c59a36634dbbe03bcf750c00d4b2ee3bc689" alt="No description"
data:image/s3,"s3://crabby-images/fd712/fd71285b2c957c15f69526c045f6673cea47e4c5" alt="No description"
you weer right
data:image/s3,"s3://crabby-images/f2075/f2075452ee21bd1691ee31f735eb290a872692ef" alt="No description"
but why does the actual app not work then?