Transformations

A condition's transformations run in order on a copy of each field's value. Results are cached per field and step prefix, so rules that share leading steps share the work. The descriptions below state each transformation’s behavior; compatibility fixtures cover the supported ModSecurity cases.

Transformation Since Description
UriDecode 1.0.0-alpha4 Decodes percent-encoded bytes, %u escapes and plus signs using the URL decoding compatibility rules.
HtmlEntityDecode 1.0.0-alpha4 Decodes named and numeric HTML entities, including entities without a trailing semicolon.
Lowercase 1.0.0-alpha4 Converts the value to lowercase using invariant rules.
UnicodeNormalize 1.0.0-alpha4 Applies Unicode NFKC normalisation.
RemoveNulls 1.0.0-alpha4 Removes NUL characters.
CompressWhitespace 1.0.0-alpha4 Collapses every run of whitespace, line breaks included, into one space.
NormalizePath 1.0.0-alpha4 Converts backslashes to slashes and resolves dot segments and repeated slashes in a path.
Base64Decode 1.0.0-alpha4 Decodes a base64 prefix, ignoring ASCII whitespace and stopping at padding or an invalid character, within the decoded-size limit.
JsDecode 1.0.0-alpha4 Decodes JavaScript hexadecimal, Unicode, octal and simple escapes using the compatibility decoder.
CssDecode 1.0.0-alpha4 Decodes CSS hexadecimal and character escapes using the compatibility decoder.
EscapeSeqDecode 1.0.0-alpha4 Decodes ANSI C hexadecimal, octal and simple escape sequences.
HexDecode 1.0.0-alpha4 Decodes pairs as bytes and reads the result as UTF-8, ignoring an unmatched final character.
Utf8ToUnicode 1.0.0-alpha4 Rewrites each non-ASCII Unicode scalar as a %u escape with at least four hexadecimal digits.
CmdLine 1.0.0-alpha4 Normalises command lines: removes backslashes, quotes and carets, turns commas and semicolons into spaces, collapses whitespace, removes spaces before slashes and parentheses, and lowercases.
RemoveWhitespace 1.0.0-alpha4 Removes all whitespace.
ReplaceComments 1.0.0-alpha4 Replaces each C-style comment with a single space.
RemoveCommentsChar 1.0.0-alpha4 Removes comment markers: /*, */, -- and #.
Base64UrlDecode 1.0.0-alpha4 Decodes a base64url prefix with optional padding, ignoring ASCII whitespace, within the decoded-size limit.
Base64AutoDecode 1.0.0-alpha4 Decodes sufficiently long base64 or base64url runs only when their decoded bytes are printable UTF-8 text.
Decompress 1.0.0-alpha4 Detects gzip or zlib-wrapped deflate by its header, otherwise tries Brotli, and retains the decoded prefix within the decompression settings.
Utf8BytesAsLatin1 1.0.0-alpha4 Produces a byte view in which each UTF-8 byte becomes one character.
Utf8LowByteTruncation 1.0.0-alpha4 Keeps each character's low byte, which reveals CRLF smuggled as U+560A or U+560D.
EvaluateLookups 1.0.0-alpha4 Folds Log4j and expression-language lookups such as $, $ and $ under depth and size caps.
FoldExpressionStrings 1.0.0-alpha4 Folds string concatenation and escapes inside quotes, such as 'a'+'b' and \x5f.
ExtractSerializedTypeNames 1.0.0-alpha4 Outputs the type names found in Java serialization, .NET NRBF, Python pickle, YAML tags and PHP serialized objects; nothing is deserialized.
UriScheme 1.0.0-alpha4 Returns the scheme from the engine's WHATWG-style URL parser, or an empty value if parsing fails.
UriHost 1.0.0-alpha4 Returns the host from the engine's WHATWG-style URL parser, or an empty value if parsing fails.