Rule flow
Conditions
All conditions of a rule must match. A rule using another scope, an operand or matchEachField: true keeps its written condition order so later conditions can use earlier matches and captures. A rule matches at most once per transaction, even if multiple values or body windows match.
Selecting fields
Each entry in targets selects a target and optionally one of name, namePrefix or nameRegex. excludeNames removes names with entries shaped as { "exact": "name" }, { "prefix": "prefix" } or { "regex": "pattern" }. Header names compare without case; other named targets use ordinal comparison. Regex selectors use the same bounded regex implementation as SafeRegex.
Args and ArgNames expand to argument targets from the current inspection stage. A RequestBody rule can also explicitly select metadata-only targets such as Method and HeaderValue to combine the original request context with parsed body fields. Targets shared with the body stage, such as parser facts, use the body stage’s values. Args and ArgNames are selectors, not fields an integrity vector can supply. See Targets for group membership and which targets support names.
Groups and scope
scope defaults to AllFields. MatchedFields selects the exact fields that matched the previous condition. SameGroup selects fields sharing a group with a previous match; group zero does not join unrelated fields.
A multipart part is one group. JSON values share their nearest enclosing object’s group; each object in an array has its own group. Query and form parameter occurrences, headers and cookies have separate groups. XML groups follow elements; GraphQL argument values share their field’s group.
These RequestBody conditions match a .php filename only when the same part’s inspected content contains <?php. A filename in one part cannot combine with content in another. File-content extraction is bounded by the system resource settings.
[
{
"targets": [
{
"target": "MultipartFileName"
}
],
"operator": {
"kind": "EndsWith",
"value": ".php"
}
},
{
"targets": [
{
"target": "MultipartFileContent"
}
],
"operator": {
"kind": "Contains",
"value": "<?php"
},
"scope": "SameGroup"
}
]
Captures and operands
SafeRegex exposes named groups such as (?<expected>.+). Repeated captures retain their last value. A later comparison uses operator.operand.capture; the capture must have been declared by an earlier condition. Scope also restricts which captured fields can supply the operand.
This comparison matches when the Host header equals a value captured from X-Expected-Host:
[
{
"targets": [
{
"target": "HeaderValue",
"name": "x-expected-host"
}
],
"operator": {
"kind": "SafeRegex",
"value": "^(?<expected>.+)$"
}
},
{
"targets": [
{
"target": "HeaderValue",
"name": "host"
}
],
"operator": {
"kind": "Equal",
"operand": {
"capture": "expected"
}
}
}
]
To read a field directly, use operator.operand.valueFrom with a concrete target and optional exact name. It reads available fields from the current stage or request metadata. It cannot use prefix/regex names, excluded names or selector groups. This example compares X-Forwarded-Host with Host; it does not establish that either header is trusted:
[
{
"targets": [
{
"target": "HeaderValue",
"name": "x-forwarded-host"
}
],
"operator": {
"kind": "Equal",
"operand": {
"valueFrom": {
"target": "HeaderValue",
"name": "host"
}
}
}
}
]
Transformations
Transformations run in listed order. Normally the operator sees the final value. With matchEachTransformation: true, it can match the original value and the intermediate transformed values. See Transformations for supported steps.
Operators and negation
Put kind and its inputs inside operator. Depending on the kind, use value, values, a named list, a numeric number, ignoreCase or an operand; unsupported combinations fail compilation. negated belongs to the condition. By default, a negated comparison succeeds when no selected value matches, which can include an empty selection. With matchEachField: true, negation instead retains each selected field whose value does not match; an empty selection does not match. A later MatchedFields condition can then inspect only those retained fields. Scoped conditions cannot follow aggregate negation, and negated regex conditions do not declare captures.
reasonCode is a condition-level diagnostic label. A detector can provide a more specific pattern reason. See Operators for the operator inventory and value shapes.