WAF inspected traffic
Each WAF policy controls how Edge inspects client WebSocket messages, gRPC messages and large request bodies on the routes it reaches. Inspection requires an applicable active ruleset. The ordinary request-body mode does not turn off WebSocket or binary gRPC inspection; the WebSocket switch is separate. Start in Detection and review WAF detections before promoting to Prevention.
GraphQL request bodies
A JSON request body whose query string parses as a GraphQL document is inspected as GraphQL. Injection rules check each argument value and variable default instead of the raw query text, so ordinary field selections such as user(id: "1") { name } do not look like SQL or shell syntax. Variables in the variables object remain JSON values. If the query contains # comments, fails to parse or exceeds a GraphQL limit, the raw query string stays inspected as a JSON value as well.
WebSocket, gRPC and large bodies
WebSocket messages
With Inspect WebSocket messages on, each client message is inspected separately against the WAF policy captured when the connection opened. In Prevention, a blocking message closes the connection with status 1008 and records ConnectionClosed; Detection records findings and forwards the message.
Messages larger than Maximum WebSocket message bytes are inspected up to that cap and raise websocket-message-too-large. Inspected routes remove permessage-deflate negotiation. Upstream-to-client WebSocket messages pass through.
gRPC streams
Edge inspects binary gRPC and binary gRPC-Web messages as they stream, without buffering or replaying the entire request. Protocol-buffer values are identified by field-number paths, without requiring a schema. Text-mode base64 gRPC-Web is outside this binary message parser.
Each message is inspected up to Maximum gRPC message bytes. Messages beyond Inspected gRPC messages pass through and raise grpc-messages-uninspected. Scores accumulate within the request, and a rule scores once even if later messages also match it. A Prevention block returns HTTP 200 with grpc-status: 7 before the response starts; an already-started response is aborted.
For plain-HTTP gRPC upstreams, select HTTP/2 in the cluster's Upstream protocol setting. It forces HTTP/2, including prior-knowledge h2c. Auto keeps normal protocol negotiation.
Bodies above the limit
For Bodies above the limit, Block rejects an oversized body in Prevention. Inspect prefix inspects the available prefix, raises body-inspection-truncated when inspection is truncated, and forwards the remaining original bytes. Structured parsing stops at the policy's body limit. Active ruleset profiles can lower the effective body limit when the action is Block. With Disk spool, raw windows and multipart inspection can continue up to Maximum spooled inspection bytes, subject to the normal parser and raw-character limits.
Disk spooling bounds retained inspection data; it does not require the whole body to fit in memory. Explicit inspection work-budget exhaustion still fails closed when the policy can block.
Container labels
Docker-discovered routes set these options with the clearplane.proxy.waf.request-body.*, waf.websocket.* and waf.grpc.* labels and clearplane.proxy.upstream.protocol. See the configuration catalog for the full route configuration.
Responses
With Response inspection set to Headers, Edge inspects the upstream status and headers before sending them. Headers and body also holds inspectable bodies until inspection finishes. This adds the time needed to receive and inspect the buffered body before the client sees it. Start in Detection to review matches before enabling Prevention.
Up to Maximum response body bytes, Edge buffers text/*, JSON (application/json and +json types), XML (application/xml and +xml types), and JavaScript (application/javascript or application/x-javascript). Other content types receive status and header inspection only. Upstream-compressed bodies are decompressed for inspection within the Firewall decoding limits; allowed responses retain their original encoded bytes.
If response capture cannot reserve memory, a policy eligible to block can reject it before the response starts; Detection and already-started responses continue with the original bytes and a budget finding. A response denied capture admission is not cached.
In Prevention, a fully buffered response that reaches the blocking threshold is replaced whole with Clearplane's block page. No byte of that upstream body reaches the client. Larger responses are inspected on a bounded prefix and their decision is logged only. Server-sent events (text/event-stream) and gRPC responses pass through immediately while Edge captures a bounded copy. Once streaming starts, response inspection cannot replace the response.
Every response is a separate transaction that uses Combined scoring against the policy's Response threshold, regardless of its request scoring mode, with its paranoia levels. Only Prevention rulesets can contribute blocking scores under a policy in Prevention.
Response inspection requires applicable active response rules, such as clearplane-data-leakage. The dashboard warns when response inspection is enabled on routes but no active ruleset contains response rules. A Detection ruleset counts because its response findings are still scored and logged.
Response inspection runs before cache storage and response compression. Cache hits reuse the inspected result; they are not inspected again. Changes to the response policy or active rulesets invalidate the applicable cache entries, and entries remain scoped to the originating request's method, path and origin. Background refreshes are inspected too. Block replacements and responses with a log-only decision that would have blocked are not stored.
Docker-discovered routes use clearplane.proxy.waf.response.inspection, response.threshold and response.maximum-body-bytes.
See Targets for the fields available at each inspection stage and Facts and limits for parser outcomes and resource bounds.