Re: [mod-security-users] issue with response body processing
Brought to you by:
victorhora,
zimmerletw
From: Christian F. <chr...@ti...> - 2015-10-19 04:03:57
|
Hello, On Mon, Oct 19, 2015 at 02:52:03PM +1100, Alex wrote: > Thank you for the followup. There is no reverse proxy setup in place, > modsecurity is running on the application server. Does this change > anything? Well, the doc says: "This directive is necessary in reverse proxy mode when the backend servers support response compression, but you wish to inspect response bodies. Unless you disable backend compression, ModSecurity will only see compressed content, which is not very useful. This directive is not necessary in embedded mode, because ModSecurity performs inspection before response compression takes place." So technically, you should not have your problem in the first place. So maybe it is not the compression after all. The match in your response body suggests binary, but not quite. What is this actually? Request and Response headers would be welcome. Ahoj, Christian -- When there are too many policemen, there can be no liberty. When there are too many soldiers, there can be no peace. When there are too many lawyers, there can be no justice. -- Lin Yutang |