Transformations
A condition's transformations run in order on a copy of each field's value. Results are cached per field and step prefix, so rules that share leading steps share the work. The descriptions below state each transformation’s behavior; compatibility fixtures cover the supported ModSecurity cases.
| Transformation | Since | Description |
|---|---|---|
UriDecode |
1.0.0-alpha4 | Decodes percent-encoded bytes, %u escapes and plus signs using the URL decoding compatibility rules. |
HtmlEntityDecode |
1.0.0-alpha4 | Decodes named and numeric HTML entities, including entities without a trailing semicolon. |
Lowercase |
1.0.0-alpha4 | Converts the value to lowercase using invariant rules. |
UnicodeNormalize |
1.0.0-alpha4 | Applies Unicode NFKC normalisation. |
RemoveNulls |
1.0.0-alpha4 | Removes NUL characters. |
CompressWhitespace |
1.0.0-alpha4 | Collapses every run of whitespace, line breaks included, into one space. |
NormalizePath |
1.0.0-alpha4 | Converts backslashes to slashes and resolves dot segments and repeated slashes in a path. |
Base64Decode |
1.0.0-alpha4 | Decodes a base64 prefix, ignoring ASCII whitespace and stopping at padding or an invalid character, within the decoded-size limit. |
JsDecode |
1.0.0-alpha4 | Decodes JavaScript hexadecimal, Unicode, octal and simple escapes using the compatibility decoder. |
CssDecode |
1.0.0-alpha4 | Decodes CSS hexadecimal and character escapes using the compatibility decoder. |
EscapeSeqDecode |
1.0.0-alpha4 | Decodes ANSI C hexadecimal, octal and simple escape sequences. |
HexDecode |
1.0.0-alpha4 | Decodes pairs as bytes and reads the result as UTF-8, ignoring an unmatched final character. |
Utf8ToUnicode |
1.0.0-alpha4 | Rewrites each non-ASCII Unicode scalar as a %u escape with at least four hexadecimal digits. |
CmdLine |
1.0.0-alpha4 | Normalises command lines: removes backslashes, quotes and carets, turns commas and semicolons into spaces, collapses whitespace, removes spaces before slashes and parentheses, and lowercases. |
RemoveWhitespace |
1.0.0-alpha4 | Removes all whitespace. |
ReplaceComments |
1.0.0-alpha4 | Replaces each C-style comment with a single space. |
RemoveCommentsChar |
1.0.0-alpha4 | Removes comment markers: /*, */, -- and #. |
Base64UrlDecode |
1.0.0-alpha4 | Decodes a base64url prefix with optional padding, ignoring ASCII whitespace, within the decoded-size limit. |
Base64AutoDecode |
1.0.0-alpha4 | Decodes sufficiently long base64 or base64url runs only when their decoded bytes are printable UTF-8 text. |
Decompress |
1.0.0-alpha4 | Detects gzip or zlib-wrapped deflate by its header, otherwise tries Brotli, and retains the decoded prefix within the decompression settings. |
Utf8BytesAsLatin1 |
1.0.0-alpha4 | Produces a byte view in which each UTF-8 byte becomes one character. |
Utf8LowByteTruncation |
1.0.0-alpha4 | Keeps each character's low byte, which reveals CRLF smuggled as U+560A or U+560D. |
EvaluateLookups |
1.0.0-alpha4 | Folds Log4j and expression-language lookups such as $, $ and $ under depth and size caps. |
FoldExpressionStrings |
1.0.0-alpha4 | Folds string concatenation and escapes inside quotes, such as 'a'+'b' and \x5f. |
ExtractSerializedTypeNames |
1.0.0-alpha4 | Outputs the type names found in Java serialization, .NET NRBF, Python pickle, YAML tags and PHP serialized objects; nothing is deserialized. |
UriScheme |
1.0.0-alpha4 | Returns the scheme from the engine's WHATWG-style URL parser, or an empty value if parsing fails. |
UriHost |
1.0.0-alpha4 | Returns the host from the engine's WHATWG-style URL parser, or an empty value if parsing fails. |