Protocol ruleset
clearplane-protocol combines HTTP policy and evasion checks with parser and framing facts. In Prevention, a critical protocol finding reaches the default request threshold of 5. JSON, XML, GraphQL, multipart and decompression limits can therefore block a request whose remaining content cannot be inspected.
Methods and content types
A WAF policy can allow methods and request content types beyond the ruleset's policy. In the policy under Firewall โ WAF policies, add Additional allowed methods, such as PROPFIND for WebDAV, and Additional request content types, such as text/plain. Docker-discovered routes use the clearplane.proxy.waf.allowed-methods and clearplane.proxy.waf.allowed-request-content-types labels.
Paranoia levels and compatibility
The default CRS charset, extension and restricted-header policies are opinionated. Review WebDAV, method overrides and uncommon media types before promotion. Inspect-prefix traffic can still block when a rule scores its truncation fact.
Start in Detection, review detections, and configure only the exclusions needed for the affected route and field.
See the measured coverage for the exact tested payload hashes, missed detections and false-positive rates. Ruleset operation explains activation, stages and rollback.