API specification validation
-
Representational State Transfer (REST)
-
Google Remote Procedure Call (gRPC)
-
Open API (formerly known as Swagger)
-
ProtoBuf (Protocol Buffers)
Assign API Spec to a profile using CLI
set appfw profile <Profile Name> -apispec <API spec entity name>
- Profile name - The name of the profile.
- API spec entity name - The name of the entity that is created from the uploaded API specification.
Assign API Spec to a profile using GUI
-
Navigate to Security > NetScaler Web App Firewall > Profiles and click Add.
-
Select the required file for an API Spec Schema and click Ok
Assign API Spec to an existing profile using GUI
-
Navigate to Security > NetScaler Web App Firewall > Profiles
-
Select a user-defined profile and click Edit.
-
On the NetScaler Web App Firewall Profile page, click the Edit icon.
-
Select the required file for an API Spec Schema and click Ok.
Configure REST and gRPC API schema validation using CLI
set appfw profile <profile name> -restAction [block log none stats]
set appfw profile <profile name> -grpcAction [block log none stats]
Configure REST and gRPC API schema validation using GUI
-
Navigate to Security > NetScaler Web App Firewall > Profiles**.
-
Select a user-defined profile and click Edit.
-
On the NetScaler Web App Firewall Profile page, Under the Advanced Settings section, click Security Checks.
-
In the Security Checks section, select REST API Schema Validation or gRPC API Schema Validation and Click Action Settings.
-
In the Actions page, set the Action parameter. You can either select or clear the option.
-
Click Ok.
Configure relaxation rule for API schema validation using CLI
bind appfw profile <profile name> -restValidation <REST relaxation pattern> -ruleAction <Log|None>
-
REST relaxation pattern - The URL pattern for which the relaxation is applied. Patterns can include variables as well as wildcard definitions, as described in proto of Google APIs Current link:
<https://github.com/googleapis/googleapis/blob/master/google/api/http.proto>The URL specified is not required to be part of the API specification.Note: The prefix of the pattern should have an HTTP method (ie. GET, PUT, POST, DELETE, PATCH) followed by a colon (:). Example:-
GET:/v1/{name=messages/*} - Allows three segment URLs starting with /v1/messages and the method is GET.
-
PATCH:/v1/messages/{message_id=**} - Allows anything with /v1/messages prefix and the method is PATCH.
-
POST:/v1/lists/** - Allows anything with /v1/lists prefix and the method is POST.
-
://engineering/**- Allows any URL that has the second segment as engineering regardless of the method.
-
-
Log or None - Specifies whether logs are generated for bypassed traffic matching the rule. When action is set to log, relaxed URLs and corresponding rules are dumped into system logs. When the action is set to log, the relaxed URLs and the corresponding rule are recorded in the system logs.
bind appfw profile <profile name> -grpcValidation <gRPC pattern> -ruleAction <Log|None>
-
gRPC pattern - The pattern of gRPC endpoint(s) for which the relaxation is applied. The gRPC method specified is not required to be part of the API specification.Example:
-
citrix.api.doc.AddBook - Allows the RPC AddBook in package citrix.api.doc.
-
test.api.** - Allows all RPCs in packages, starting with test.api.
-
.engineering.* - Allows all RPCs that have engineering as the second segment of the package name.
-
-
Log|None - Specifies whether logs are generated for bypassed traffic matching the rule.
Configure relaxation rule for API schema validation using GUI
REST API schema validation
-
Navigate to Security > NetScaler Web App Firewall > Profiles.
-
Select a user-defined profile and click Edit.
-
On the NetScaler Web App Firewall Profile page, Under the Advanced Settings section, click Relaxation Rule.
-
Select the REST API Schema Validation and click Edit.
-
In the REST API Schema Validation Relaxation Rules page, click Add.
-
In the REST API Schema Validation Relaxation Rule page, specify the following details:
-
Enabled - Select the option to enable the relaxation rule.
-
Rest URL Pattern - Enter the URL pattern for which the relaxation is applied.
-
REST URL Relaxation Action - Select an action.
-
Comments- Description of the expression.
-
Resource ID - Unique ID to identify the resource.
-
Click Create. The newly added REST API schema validation relaxation rule is listed on the REST API Schema Validation Relaxation Rules page.
-
gRPC API schema validation
-
Navigate to Security > NetScaler Web App Firewall > Profiles.
-
On the Profiles page, select a profile and click Edit.
-
On the NetScaler Web App Firewall Profile page, under the Advanced Settings section, click Relaxation Rule.
-
Select the gRPC API Schema Validation and click Edit.
-
In the gRPC API Schema Validation Relaxation Rules page, click Add.
-
In the gRPC API Schema Validation Relaxation Rule page, specify the following details:
-
Enabled - Select the option to enable the relaxation rule.
-
gRPC Method Pattern - Enter the gRPC Method pattern for which the relaxation is applied
-
REST URL Relaxation Action - Select any one of the actions.
-
Comments- Description of the expression.
-
Resource ID - Unique ID to identify the resource.
-
Click Create. The newly added gRPC API schema validation relaxation rule is listed in the gRPC API Schema Validation Relaxation Rules page.
-