%% WARNING: DO NOT EDIT, AUTO-GENERATED CODE! %% See https://github.com/jkakar/aws-codegen for more details. %% @doc This is the AWS WAF API Reference. This guide is for %% developers who need detailed information about the AWS WAF API actions, %% data types, and errors. For detailed information about AWS WAF features %% and an overview of how to use the AWS WAF API, see the AWS WAF %% Developer Guide. -module(aws_waf). -export([create_byte_match_set/2, create_byte_match_set/3, create_i_p_set/2, create_i_p_set/3, create_rule/2, create_rule/3, create_size_constraint_set/2, create_size_constraint_set/3, create_sql_injection_match_set/2, create_sql_injection_match_set/3, create_web_a_c_l/2, create_web_a_c_l/3, delete_byte_match_set/2, delete_byte_match_set/3, delete_i_p_set/2, delete_i_p_set/3, delete_rule/2, delete_rule/3, delete_size_constraint_set/2, delete_size_constraint_set/3, delete_sql_injection_match_set/2, delete_sql_injection_match_set/3, delete_web_a_c_l/2, delete_web_a_c_l/3, get_byte_match_set/2, get_byte_match_set/3, get_change_token/2, get_change_token/3, get_change_token_status/2, get_change_token_status/3, get_i_p_set/2, get_i_p_set/3, get_rule/2, get_rule/3, get_sampled_requests/2, get_sampled_requests/3, get_size_constraint_set/2, get_size_constraint_set/3, get_sql_injection_match_set/2, get_sql_injection_match_set/3, get_web_a_c_l/2, get_web_a_c_l/3, list_byte_match_sets/2, list_byte_match_sets/3, list_i_p_sets/2, list_i_p_sets/3, list_rules/2, list_rules/3, list_size_constraint_sets/2, list_size_constraint_sets/3, list_sql_injection_match_sets/2, list_sql_injection_match_sets/3, list_web_a_c_ls/2, list_web_a_c_ls/3, update_byte_match_set/2, update_byte_match_set/3, update_i_p_set/2, update_i_p_set/3, update_rule/2, update_rule/3, update_size_constraint_set/2, update_size_constraint_set/3, update_sql_injection_match_set/2, update_sql_injection_match_set/3, update_web_a_c_l/2, update_web_a_c_l/3]). -include_lib("hackney/include/hackney_lib.hrl"). %%==================================================================== %% API %%==================================================================== %% @doc Creates a ByteMatchSet. You then use %% UpdateByteMatchSet to identify the part of a web request that you %% want AWS WAF to inspect, such as the values of the User-Agent %% header or the query string. For example, you can create a %% ByteMatchSet that matches any requests with %% User-Agent headers that contain the string %% BadBot. You can then configure AWS WAF to reject those %% requests. %% %% To create and configure a ByteMatchSet, perform the following %% steps: %% %%
  1. Use GetChangeToken to get the change token that you %% provide in the ChangeToken parameter of a %% CreateByteMatchSet request.
  2. Submit a %% CreateByteMatchSet request.
  3. Use %% GetChangeToken to get the change token that you provide in %% the ChangeToken parameter of an %% UpdateByteMatchSet request.
  4. Submit an %% UpdateByteMatchSet request to specify the part of the request that %% you want AWS WAF to inspect (for example, the header or the URI) and the %% value that you want AWS WAF to watch for.
For more information %% about how to use the AWS WAF API to allow or block HTTP requests, see the %% AWS WAF %% Developer Guide. create_byte_match_set(Client, Input) when is_map(Client), is_map(Input) -> create_byte_match_set(Client, Input, []). create_byte_match_set(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"CreateByteMatchSet">>, Input, Options). %% @doc Creates an IPSet, which you use to specify which web requests %% you want to allow or block based on the IP addresses that the requests %% originate from. For example, if you're receiving a lot of requests from %% one or more individual IP addresses or one or more ranges of IP addresses %% and you want to block the requests, you can create an IPSet %% that contains those IP addresses and then configure AWS WAF to block the %% requests. %% %% To create and configure an IPSet, perform the following %% steps: %% %%
  1. Use GetChangeToken to get the change token that you %% provide in the ChangeToken parameter of a %% CreateIPSet request.
  2. Submit a %% CreateIPSet request.
  3. Use GetChangeToken %% to get the change token that you provide in the ChangeToken %% parameter of an UpdateIPSet request.
  4. Submit an %% UpdateIPSet request to specify the IP addresses that you want %% AWS WAF to watch for.
For more information about how to use the %% AWS WAF API to allow or block HTTP requests, see the AWS WAF %% Developer Guide. create_i_p_set(Client, Input) when is_map(Client), is_map(Input) -> create_i_p_set(Client, Input, []). create_i_p_set(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"CreateIPSet">>, Input, Options). %% @doc Creates a Rule, which contains the IPSet %% objects, ByteMatchSet objects, and other predicates that %% identify the requests that you want to block. If you add more than one %% predicate to a Rule, a request must match all of the %% specifications to be allowed or blocked. For example, suppose you add the %% following to a Rule: %% %% You then add the Rule to a WebACL and %% specify that you want to blocks requests that satisfy the %% Rule. For a request to be blocked, it must come from the IP %% address 192.0.2.44 and the User-Agent header in the %% request must contain the value BadBot. %% %% To create and configure a Rule, perform the following steps: %% %%
  1. Create and update the predicates that you want to include in the %% Rule. For more information, see CreateByteMatchSet, %% CreateIPSet, and CreateSqlInjectionMatchSet.
  2. Use %% GetChangeToken to get the change token that you provide in the %% ChangeToken parameter of a CreateRule %% request.
  3. Submit a CreateRule request.
  4. Use %% GetChangeToken to get the change token that you provide in %% the ChangeToken parameter of an UpdateRule %% request.
  5. Submit an UpdateRule request to specify the %% predicates that you want to include in the Rule.
  6. %%
  7. Create and update a WebACL that contains the %% Rule. For more information, see CreateWebACL.
  8. %%
For more information about how to use the AWS WAF API to allow or %% block HTTP requests, see the AWS WAF %% Developer Guide. create_rule(Client, Input) when is_map(Client), is_map(Input) -> create_rule(Client, Input, []). create_rule(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"CreateRule">>, Input, Options). %% @doc Creates a SizeConstraintSet. You then use %% UpdateSizeConstraintSet to identify the part of a web request that %% you want AWS WAF to check for length, such as the length of the %% User-Agent header or the length of the query string. For %% example, you can create a SizeConstraintSet that matches any %% requests that have a query string that is longer than 100 bytes. You can %% then configure AWS WAF to reject those requests. %% %% To create and configure a SizeConstraintSet, perform the %% following steps: %% %%
  1. Use GetChangeToken to get the change token that you %% provide in the ChangeToken parameter of a %% CreateSizeConstraintSet request.
  2. Submit a %% CreateSizeConstraintSet request.
  3. Use %% GetChangeToken to get the change token that you provide in %% the ChangeToken parameter of an %% UpdateSizeConstraintSet request.
  4. Submit an %% UpdateSizeConstraintSet request to specify the part of the request %% that you want AWS WAF to inspect (for example, the header or the URI) and %% the value that you want AWS WAF to watch for.
For more %% information about how to use the AWS WAF API to allow or block HTTP %% requests, see the AWS WAF %% Developer Guide. create_size_constraint_set(Client, Input) when is_map(Client), is_map(Input) -> create_size_constraint_set(Client, Input, []). create_size_constraint_set(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"CreateSizeConstraintSet">>, Input, Options). %% @doc Creates a SqlInjectionMatchSet, which you use to allow, block, %% or count requests that contain snippets of SQL code in a specified part of %% web requests. AWS WAF searches for character sequences that are likely to %% be malicious strings. %% %% To create and configure a SqlInjectionMatchSet, perform the %% following steps: %% %%
  1. Use GetChangeToken to get the change token that you %% provide in the ChangeToken parameter of a %% CreateSqlInjectionMatchSet request.
  2. Submit a %% CreateSqlInjectionMatchSet request.
  3. Use %% GetChangeToken to get the change token that you provide in %% the ChangeToken parameter of an %% UpdateSqlInjectionMatchSet request.
  4. Submit an %% UpdateSqlInjectionMatchSet request to specify the parts of web %% requests in which you want to allow, block, or count malicious SQL %% code.
For more information about how to use the AWS WAF API to %% allow or block HTTP requests, see the AWS WAF %% Developer Guide. create_sql_injection_match_set(Client, Input) when is_map(Client), is_map(Input) -> create_sql_injection_match_set(Client, Input, []). create_sql_injection_match_set(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"CreateSqlInjectionMatchSet">>, Input, Options). %% @doc Creates a WebACL, which contains the Rules %% that identify the CloudFront web requests that you want to allow, block, %% or count. AWS WAF evaluates Rules in order based on the value %% of Priority for each Rule. %% %% You also specify a default action, either ALLOW or %% BLOCK. If a web request doesn't match any of the %% Rules in a WebACL, AWS WAF responds to the %% request with the default action. %% %% To create and configure a WebACL, perform the following %% steps: %% %%
  1. Create and update the ByteMatchSet objects and other %% predicates that you want to include in Rules. For more %% information, see CreateByteMatchSet, UpdateByteMatchSet, %% CreateIPSet, UpdateIPSet, CreateSqlInjectionMatchSet, %% and UpdateSqlInjectionMatchSet.
  2. Create and update the %% Rules that you want to include in the WebACL. %% For more information, see CreateRule and UpdateRule.
  3. %%
  4. Use GetChangeToken to get the change token that you provide in %% the ChangeToken parameter of a CreateWebACL %% request.
  5. Submit a CreateWebACL request.
  6. Use %% GetChangeToken to get the change token that you provide in %% the ChangeToken parameter of an UpdateWebACL %% request.
  7. Submit an UpdateWebACL request to specify the %% Rules that you want to include in the WebACL, to %% specify the default action, and to associate the WebACL with %% a CloudFront distribution.
For more information about how to %% use the AWS WAF API, see the AWS WAF %% Developer Guide. create_web_a_c_l(Client, Input) when is_map(Client), is_map(Input) -> create_web_a_c_l(Client, Input, []). create_web_a_c_l(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"CreateWebACL">>, Input, Options). %% @doc Permanently deletes a ByteMatchSet. You can't delete a %% ByteMatchSet if it's still used in any Rules or %% if it still includes any ByteMatchTuple objects (any filters). %% %% If you just want to remove a ByteMatchSet from a %% Rule, use UpdateRule. %% %% To permanently delete a ByteMatchSet, perform the following %% steps: %% %%
  1. Update the ByteMatchSet to remove filters, if any. %% For more information, see UpdateByteMatchSet.
  2. Use %% GetChangeToken to get the change token that you provide in the %% ChangeToken parameter of a DeleteByteMatchSet %% request.
  3. Submit a DeleteByteMatchSet request.
  4. %%
delete_byte_match_set(Client, Input) when is_map(Client), is_map(Input) -> delete_byte_match_set(Client, Input, []). delete_byte_match_set(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"DeleteByteMatchSet">>, Input, Options). %% @doc Permanently deletes an IPSet. You can't delete an %% IPSet if it's still used in any Rules or if it %% still includes any IP addresses. %% %% If you just want to remove an IPSet from a Rule, %% use UpdateRule. %% %% To permanently delete an IPSet from AWS WAF, perform the %% following steps: %% %%
  1. Update the IPSet to remove IP address ranges, if %% any. For more information, see UpdateIPSet.
  2. Use %% GetChangeToken to get the change token that you provide in the %% ChangeToken parameter of a DeleteIPSet %% request.
  3. Submit a DeleteIPSet request.
delete_i_p_set(Client, Input) when is_map(Client), is_map(Input) -> delete_i_p_set(Client, Input, []). delete_i_p_set(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"DeleteIPSet">>, Input, Options). %% @doc Permanently deletes a Rule. You can't delete a %% Rule if it's still used in any WebACL objects or %% if it still includes any predicates, such as ByteMatchSet %% objects. %% %% If you just want to remove a Rule from a WebACL, %% use UpdateWebACL. %% %% To permanently delete a Rule from AWS WAF, perform the %% following steps: %% %%
  1. Update the Rule to remove predicates, if any. For %% more information, see UpdateRule.
  2. Use %% GetChangeToken to get the change token that you provide in the %% ChangeToken parameter of a DeleteRule %% request.
  3. Submit a DeleteRule request.
delete_rule(Client, Input) when is_map(Client), is_map(Input) -> delete_rule(Client, Input, []). delete_rule(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"DeleteRule">>, Input, Options). %% @doc Permanently deletes a SizeConstraintSet. You can't delete a %% SizeConstraintSet if it's still used in any %% Rules or if it still includes any SizeConstraint %% objects (any filters). %% %% If you just want to remove a SizeConstraintSet from a %% Rule, use UpdateRule. %% %% To permanently delete a SizeConstraintSet, perform the %% following steps: %% %%
  1. Update the SizeConstraintSet to remove filters, if %% any. For more information, see UpdateSizeConstraintSet.
  2. %%
  3. Use GetChangeToken to get the change token that you provide in %% the ChangeToken parameter of a %% DeleteSizeConstraintSet request.
  4. Submit a %% DeleteSizeConstraintSet request.
delete_size_constraint_set(Client, Input) when is_map(Client), is_map(Input) -> delete_size_constraint_set(Client, Input, []). delete_size_constraint_set(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"DeleteSizeConstraintSet">>, Input, Options). %% @doc Permanently deletes a SqlInjectionMatchSet. You can't delete a %% SqlInjectionMatchSet if it's still used in any %% Rules or if it still contains any %% SqlInjectionMatchTuple objects. %% %% If you just want to remove a SqlInjectionMatchSet from a %% Rule, use UpdateRule. %% %% To permanently delete a SqlInjectionMatchSet from AWS WAF, %% perform the following steps: %% %%
  1. Update the SqlInjectionMatchSet to remove filters, %% if any. For more information, see UpdateSqlInjectionMatchSet.
  2. %%
  3. Use GetChangeToken to get the change token that you provide in %% the ChangeToken parameter of a %% DeleteSqlInjectionMatchSet request.
  4. Submit a %% DeleteSqlInjectionMatchSet request.
delete_sql_injection_match_set(Client, Input) when is_map(Client), is_map(Input) -> delete_sql_injection_match_set(Client, Input, []). delete_sql_injection_match_set(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"DeleteSqlInjectionMatchSet">>, Input, Options). %% @doc Permanently deletes a WebACL. You can't delete a %% WebACL if it still contains any Rules. %% %% To delete a WebACL, perform the following steps: %% %%
  1. Update the WebACL to remove Rules, if %% any. For more information, see UpdateWebACL.
  2. Use %% GetChangeToken to get the change token that you provide in the %% ChangeToken parameter of a DeleteWebACL %% request.
  3. Submit a DeleteWebACL request.
delete_web_a_c_l(Client, Input) when is_map(Client), is_map(Input) -> delete_web_a_c_l(Client, Input, []). delete_web_a_c_l(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"DeleteWebACL">>, Input, Options). %% @doc Returns the ByteMatchSet specified by %% ByteMatchSetId. get_byte_match_set(Client, Input) when is_map(Client), is_map(Input) -> get_byte_match_set(Client, Input, []). get_byte_match_set(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"GetByteMatchSet">>, Input, Options). %% @doc When you want to create, update, or delete AWS WAF objects, get a %% change token and include the change token in the create, update, or delete %% request. Change tokens ensure that your application doesn't submit %% conflicting requests to AWS WAF. %% %% Each create, update, or delete request must use a unique change token. If %% your application submits a GetChangeToken request and then %% submits a second GetChangeToken request before submitting a %% create, update, or delete request, the second GetChangeToken %% request returns the same value as the first GetChangeToken %% request. %% %% When you use a change token in a create, update, or delete request, the %% status of the change token changes to PENDING, which %% indicates that AWS WAF is propagating the change to all AWS WAF servers. %% Use GetChangeTokenStatus to determine the status of your %% change token. get_change_token(Client, Input) when is_map(Client), is_map(Input) -> get_change_token(Client, Input, []). get_change_token(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"GetChangeToken">>, Input, Options). %% @doc Returns the status of a ChangeToken that you got by %% calling GetChangeToken. ChangeTokenStatus is one of %% the following values: %% %% get_change_token_status(Client, Input) when is_map(Client), is_map(Input) -> get_change_token_status(Client, Input, []). get_change_token_status(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"GetChangeTokenStatus">>, Input, Options). %% @doc Returns the IPSet that is specified by IPSetId. get_i_p_set(Client, Input) when is_map(Client), is_map(Input) -> get_i_p_set(Client, Input, []). get_i_p_set(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"GetIPSet">>, Input, Options). %% @doc Returns the Rule that is specified by the RuleId %% that you included in the GetRule request. get_rule(Client, Input) when is_map(Client), is_map(Input) -> get_rule(Client, Input, []). get_rule(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"GetRule">>, Input, Options). %% @doc Gets detailed information about a specified number of requests--a %% sample--that AWS WAF randomly selects from among the first 5,000 requests %% that your AWS resource received during a time range that you choose. You %% can specify a sample size of up to 100 requests, and you can specify any %% time range in the previous three hours. %% %% GetSampledRequests returns a time range, which is usually the %% time range that you specified. However, if your resource (such as a %% CloudFront distribution) received 5,000 requests before the specified time %% range elapsed, GetSampledRequests returns an updated time %% range. This new time range indicates the actual period during which AWS %% WAF selected the requests in the sample. get_sampled_requests(Client, Input) when is_map(Client), is_map(Input) -> get_sampled_requests(Client, Input, []). get_sampled_requests(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"GetSampledRequests">>, Input, Options). %% @doc Returns the SizeConstraintSet specified by %% SizeConstraintSetId. get_size_constraint_set(Client, Input) when is_map(Client), is_map(Input) -> get_size_constraint_set(Client, Input, []). get_size_constraint_set(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"GetSizeConstraintSet">>, Input, Options). %% @doc Returns the SqlInjectionMatchSet that is specified by %% SqlInjectionMatchSetId. get_sql_injection_match_set(Client, Input) when is_map(Client), is_map(Input) -> get_sql_injection_match_set(Client, Input, []). get_sql_injection_match_set(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"GetSqlInjectionMatchSet">>, Input, Options). %% @doc Returns the WebACL that is specified by WebACLId. get_web_a_c_l(Client, Input) when is_map(Client), is_map(Input) -> get_web_a_c_l(Client, Input, []). get_web_a_c_l(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"GetWebACL">>, Input, Options). %% @doc Returns an array of ByteMatchSetSummary objects. list_byte_match_sets(Client, Input) when is_map(Client), is_map(Input) -> list_byte_match_sets(Client, Input, []). list_byte_match_sets(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"ListByteMatchSets">>, Input, Options). %% @doc Returns an array of IPSetSummary objects in the response. list_i_p_sets(Client, Input) when is_map(Client), is_map(Input) -> list_i_p_sets(Client, Input, []). list_i_p_sets(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"ListIPSets">>, Input, Options). %% @doc Returns an array of RuleSummary objects. list_rules(Client, Input) when is_map(Client), is_map(Input) -> list_rules(Client, Input, []). list_rules(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"ListRules">>, Input, Options). %% @doc Returns an array of SizeConstraintSetSummary objects. list_size_constraint_sets(Client, Input) when is_map(Client), is_map(Input) -> list_size_constraint_sets(Client, Input, []). list_size_constraint_sets(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"ListSizeConstraintSets">>, Input, Options). %% @doc Returns an array of SqlInjectionMatchSet objects. list_sql_injection_match_sets(Client, Input) when is_map(Client), is_map(Input) -> list_sql_injection_match_sets(Client, Input, []). list_sql_injection_match_sets(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"ListSqlInjectionMatchSets">>, Input, Options). %% @doc Returns an array of WebACLSummary objects in the response. list_web_a_c_ls(Client, Input) when is_map(Client), is_map(Input) -> list_web_a_c_ls(Client, Input, []). list_web_a_c_ls(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"ListWebACLs">>, Input, Options). %% @doc Inserts or deletes ByteMatchTuple objects (filters) in a %% ByteMatchSet. For each ByteMatchTuple object, you %% specify the following values: %% %% For example, you can %% add a ByteMatchSetUpdate object that matches web requests in %% which User-Agent headers contain the string %% BadBot. You can then configure AWS WAF to block those %% requests. %% %% To create and configure a ByteMatchSet, perform the following %% steps: %% %%
  1. Create a ByteMatchSet. For more information, see %% CreateByteMatchSet.
  2. Use GetChangeToken to get the %% change token that you provide in the ChangeToken parameter of %% an UpdateByteMatchSet request.
  3. Submit an %% UpdateByteMatchSet request to specify the part of the request %% that you want AWS WAF to inspect (for example, the header or the URI) and %% the value that you want AWS WAF to watch for.
For more %% information about how to use the AWS WAF API to allow or block HTTP %% requests, see the AWS WAF %% Developer Guide. update_byte_match_set(Client, Input) when is_map(Client), is_map(Input) -> update_byte_match_set(Client, Input, []). update_byte_match_set(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"UpdateByteMatchSet">>, Input, Options). %% @doc Inserts or deletes IPSetDescriptor objects in an %% IPSet. For each IPSetDescriptor object, you %% specify the following values: %% %% AWS WAF supports /8, /16, /24, and %% /32 IP address ranges. For more information about CIDR notation, see the %% Wikipedia entry Classless %% Inter-Domain Routing. %% %% You use an IPSet to specify which web requests you want to %% allow or block based on the IP addresses that the requests originated %% from. For example, if you're receiving a lot of requests from one or a %% small number of IP addresses and you want to block the requests, you can %% create an IPSet that specifies those IP addresses, and then %% configure AWS WAF to block the requests. %% %% To create and configure an IPSet, perform the following %% steps: %% %%
  1. Submit a CreateIPSet request.
  2. Use %% GetChangeToken to get the change token that you provide in the %% ChangeToken parameter of an UpdateIPSet request.
  3. %%
  4. Submit an UpdateIPSet request to specify the IP addresses %% that you want AWS WAF to watch for.
When you update an %% IPSet, you specify the IP addresses that you want to add %% and/or the IP addresses that you want to delete. If you want to change an %% IP address, you delete the existing IP address and add the new one. %% %% For more information about how to use the AWS WAF API to allow or block %% HTTP requests, see the AWS WAF %% Developer Guide. update_i_p_set(Client, Input) when is_map(Client), is_map(Input) -> update_i_p_set(Client, Input, []). update_i_p_set(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"UpdateIPSet">>, Input, Options). %% @doc Inserts or deletes Predicate objects in a Rule. %% Each Predicate object identifies a predicate, such as a %% ByteMatchSet or an IPSet, that specifies the web requests %% that you want to allow, block, or count. If you add more than one %% predicate to a Rule, a request must match all of the %% specifications to be allowed, blocked, or counted. For example, suppose %% you add the following to a Rule: %% %% You then add the Rule to a %% WebACL and specify that you want to block requests that %% satisfy the Rule. For a request to be blocked, the %% User-Agent header in the request must contain the value %% BadBot and the request must originate from the IP %% address 192.0.2.44. %% %% To create and configure a Rule, perform the following steps: %% %%
  1. Create and update the predicates that you want to include in the %% Rule.
  2. Create the Rule. See %% CreateRule.
  3. Use GetChangeToken to get the %% change token that you provide in the ChangeToken parameter of %% an UpdateRule request.
  4. Submit an UpdateRule %% request to add predicates to the Rule.
  5. Create and %% update a WebACL that contains the Rule. See %% CreateWebACL.
If you want to replace one %% ByteMatchSet or IPSet with another, you delete %% the existing one and add the new one. %% %% For more information about how to use the AWS WAF API to allow or block %% HTTP requests, see the AWS WAF %% Developer Guide. update_rule(Client, Input) when is_map(Client), is_map(Input) -> update_rule(Client, Input, []). update_rule(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"UpdateRule">>, Input, Options). %% @doc Inserts or deletes SizeConstraint objects (filters) in a %% SizeConstraintSet. For each SizeConstraint object, you %% specify the following values: %% %% For example, you %% can add a SizeConstraintSetUpdate object that matches web %% requests in which the length of the User-Agent header is %% greater than 100 bytes. You can then configure AWS WAF to block those %% requests. %% %% To create and configure a SizeConstraintSet, perform the %% following steps: %% %%
  1. Create a SizeConstraintSet. For more information, %% see CreateSizeConstraintSet.
  2. Use GetChangeToken to %% get the change token that you provide in the ChangeToken %% parameter of an UpdateSizeConstraintSet request.
  3. %%
  4. Submit an UpdateSizeConstraintSet request to specify the %% part of the request that you want AWS WAF to inspect (for example, the %% header or the URI) and the value that you want AWS WAF to watch for.
  5. %%
For more information about how to use the AWS WAF API to allow or %% block HTTP requests, see the AWS WAF %% Developer Guide. update_size_constraint_set(Client, Input) when is_map(Client), is_map(Input) -> update_size_constraint_set(Client, Input, []). update_size_constraint_set(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"UpdateSizeConstraintSet">>, Input, Options). %% @doc Inserts or deletes SqlInjectionMatchTuple objects (filters) in %% a SqlInjectionMatchSet. For each %% SqlInjectionMatchTuple object, you specify the following %% values: %% %% You use SqlInjectionMatchSet %% objects to specify which CloudFront requests you want to allow, block, or %% count. For example, if you're receiving requests that contain snippets of %% SQL code in the query string and you want to block the requests, you can %% create a SqlInjectionMatchSet with the applicable settings, %% and then configure AWS WAF to block the requests. %% %% To create and configure a SqlInjectionMatchSet, perform the %% following steps: %% %%
  1. Submit a CreateSqlInjectionMatchSet request.
  2. Use %% GetChangeToken to get the change token that you provide in the %% ChangeToken parameter of an UpdateIPSet request.
  3. %%
  4. Submit an UpdateSqlInjectionMatchSet request to specify %% the parts of web requests that you want AWS WAF to inspect for snippets of %% SQL code.
For more information about how to use the AWS WAF API %% to allow or block HTTP requests, see the AWS WAF %% Developer Guide. update_sql_injection_match_set(Client, Input) when is_map(Client), is_map(Input) -> update_sql_injection_match_set(Client, Input, []). update_sql_injection_match_set(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"UpdateSqlInjectionMatchSet">>, Input, Options). %% @doc Inserts or deletes ActivatedRule objects in a %% WebACL. Each Rule identifies web requests that %% you want to allow, block, or count. When you update a WebACL, %% you specify the following values: %% %% To create and configure a %% WebACL, perform the following steps: %% %%
  1. Create and update the predicates that you want to include in %% Rules. For more information, see CreateByteMatchSet, %% UpdateByteMatchSet, CreateIPSet, UpdateIPSet, %% CreateSqlInjectionMatchSet, and %% UpdateSqlInjectionMatchSet.
  2. Create and update the %% Rules that you want to include in the WebACL. %% For more information, see CreateRule and UpdateRule.
  3. %%
  4. Create a WebACL. See CreateWebACL.
  5. Use %% GetChangeToken to get the change token that you provide in %% the ChangeToken parameter of an UpdateWebACL %% request.
  6. Submit an UpdateWebACL request to specify %% the Rules that you want to include in the %% WebACL, to specify the default action, and to associate the %% WebACL with a CloudFront distribution.
For more %% information about how to use the AWS WAF API to allow or block HTTP %% requests, see the AWS WAF %% Developer Guide. update_web_a_c_l(Client, Input) when is_map(Client), is_map(Input) -> update_web_a_c_l(Client, Input, []). update_web_a_c_l(Client, Input, Options) when is_map(Client), is_map(Input), is_list(Options) -> request(Client, <<"UpdateWebACL">>, Input, Options). %%==================================================================== %% Internal functions %%==================================================================== -spec request(aws_client:aws_client(), binary(), map(), list()) -> {ok, Result, {integer(), list(), hackney:client()}} | {error, Error, {integer(), list(), hackney:client()}} | {error, term()} when Result :: map() | undefined, Error :: {binary(), binary()}. request(Client, Action, Input, Options) -> Client1 = Client#{service => <<"waf">>}, Host = get_host(<<"waf">>, Client1), URL = get_url(Host, Client1), Headers = [{<<"Host">>, Host}, {<<"Content-Type">>, <<"application/x-amz-json-1.1">>}, {<<"X-Amz-Target">>, << <<"AWSWAF_20150824.">>/binary, Action/binary>>}], Payload = jsx:encode(Input), Headers1 = aws_request:sign_request(Client1, <<"POST">>, URL, Headers, Payload), Response = hackney:request(post, URL, Headers1, Payload, Options), handle_response(Response). handle_response({ok, 200, ResponseHeaders, Client}) -> case hackney:body(Client) of {ok, <<>>} -> {ok, undefined, {200, ResponseHeaders, Client}}; {ok, Body} -> Result = jsx:decode(Body, [return_maps]), {ok, Result, {200, ResponseHeaders, Client}} end; handle_response({ok, StatusCode, ResponseHeaders, Client}) -> {ok, Body} = hackney:body(Client), Error = jsx:decode(Body, [return_maps]), Exception = maps:get(<<"__type">>, Error, undefined), Reason = maps:get(<<"message">>, Error, undefined), {error, {Exception, Reason}, {StatusCode, ResponseHeaders, Client}}; handle_response({error, Reason}) -> {error, Reason}. get_host(_EndpointPrefix, #{region := <<"local">>}) -> <<"localhost">>; get_host(EndpointPrefix, #{region := Region, endpoint := Endpoint}) -> aws_util:binary_join([EndpointPrefix, <<".">>, Region, <<".">>, Endpoint], <<"">>). get_url(Host, Client) -> Proto = maps:get(proto, Client), Port = maps:get(port, Client), aws_util:binary_join([Proto, <<"://">>, Host, <<":">>, Port, <<"/">>], <<"">>).