Skip to content

@eq operator should produce a warning if used with non-numeric value #2281

Open
@martinhsv

Description

@martinhsv

The @eq operator is currently intended to be used with numeric values. But, with a name like 'eq' a rule writer may inadvertently compose a rule with something like "@eq foo" ... which is unlikely to be what the rule writer intends.

It might be helpful if use of @eq with a non-numeric value produced at least a warning message at rule-load time.

Metadata

Metadata

Assignees

Labels

3.xRelated to ModSecurity version 3.xenhancement

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions