Advanced policy expressions using API specification
http.req.api expression to identify the endpoints in the incoming requests defined in the API specification.
http.req.api (“API_Spec_Name”)
set responder policy reject -rule "!http.req.api(\"myspec\").endpoint(\"POST"\",\"/v1/pet/\").exists"
set responder policy reject -rule q{!http.req.api("myspec").endpoint("POST","/v1/pet/").exists}
POST request to the /v1/pet/ endpoint, as defined in the myspec API specification, the request is rejected.
set responder policy reject -rule !"http.req.api(\"myspec\").EXISTS
myspec API specification, the request is rejected.
Advanced policy expression for API schema
Expression to match traffic by HTTP method
-
Single HTTP method
http.req.api("petstore").method("POST").text("id").eq("1") -
Multiple Method
http.req.api("petstore").method("GET|DELETE").exists
Expression to match traffic by URL
-
http.api("petstore").path("/v1/pets/*/find")It matches the incoming traffic only with/v1/pets/*/find -
http.api("petstore").path("/v1/pets/**")It matches all endpoints starting with/v1/pets
Expression to match traffic by API name
show api spec gspec
Name: gspec
File: gfile
Type: OAS
-
The
operation IDserves as the endpoint name if the file type is OAS.Example: To validate the incoming traffic against the endpoint from the following OAS:operationId: adexchangebuyer.accounts.listUse the following policy expression:http.req.api("schema").apiname("adexchangebuyer.accounts.list").exists -
The
service nameandrpc nameserves as the endpoint name if the file type is proto.In the following example, EchoService.Echo is the endpoint: service EchoService { rpc Echo(EchoReq) returns (EchoResp) { option (google.api.http) = { get: "/v1/{name=messages/*}" }; } }
Access values from the API specification
-
num - An integer value.
-
ulong - A long integer value.
-
bool - A boolean value.
-
double - A double value.
-
text - A string of any length.
http. req.api("petstore.proto"). APIName ("TestPet").NUM("test_num1").eq(1)
Access value from the repeated fields
http.req.api("petstore.proto", "FindPets').TEXT( "tags", 5 ).contains("mytag")
/v1/pets?tags=1&tags=2&tags=3&tags=4&tags=mytag&tags=6
Access values from the nested objects
http. req.api("petstore.proto", "TestPet").text( "kennel.location.state" ).contains("California")
Access value using object expression
HTTP. req.api("schema").object("foo",1).text("bar").eq("none")