Add CENTINELA_SHUN_ON_VERDICT so one verdict need not shun a client #11
Loading…
Reference in a new issue
No description provided.
Delete branch "verdict-shun-setting"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
A single model verdict could shun a client for
CENTINELA_SHUN_TTL. An authenticated user posting a triage note to a vulnerability tracker's API was shunned twice this way. The note is prose about a Dockerfile's ENV block; CRS scored it 18 on its unix command rules and the model answeredcommand_injection=0.94. Every later request from that address, reads included, was refused on every host for 15 minutes.Change
New setting
CENTINELA_SHUN_ON_VERDICT, defaulttrue(current behaviour).With
false, a shun verdict is applied as a block:CENTINELA_SHUN_AFTER, which becomes the only thing that shunsCENTINELA_SHUN_AFTERunset, nothing shunsWhat this gives up
A client whose single request is judged command injection is no longer banned on the spot. It is banned after
CENTINELA_SHUN_AFTERblocked requests in the window. Each such request is still refused.What this does not fix
CENTINELA_SHUN_AFTERof them; it does not remove it.Tests
TestVerdictShunSettinguses the note body that caused the incident. By default the note shuns and the next read is refused. With the setting off the note is blocked, the next read is allowed, a repeat is refused from the cache as a block, and blocks still add up to a repeat-offender shun. Config default andfalseare covered.make vet,make buildandmake test(race detector) pass.Merging to
mainrunsbuild-and-push, which tags and publishes the next patch version.🔎 ojo scan results
No findings.