You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS WAF托管规则动作覆盖自定义响应失效问题咨询

问题:AWS WAF托管规则动作覆盖配置自定义响应不生效的原因及解决方案

问题背景

尝试通过CloudFormation配置AWS WAF托管规则的RuleActionOverrides,将默认Block动作替换为带自定义纯文本响应的Block,但配置后仍返回WAF默认403页面,配置代码如下:

Resources:
  Waf:
    Type: AWS::WAFv2::WebACL
    Properties:
      Scope: CLOUDFRONT
      DefaultAction:
        Allow: {} # Allow for requests that don't match any rules
      CustomResponseBodies:
        SecurityViolationError:
          ContentType: TEXT_PLAIN
          Content: Request blocked due to security concerns as it was detected as malicious.
      Rules:
        - Priority: 0
          Name: BlockSqlInjection
          OverrideAction:
            None: {}
          Statement:
            ManagedRuleGroupStatement:
              VendorName: AWS
              Name: AWSManagedRulesSQLiRuleSet
              Version: Version_2.0
              RuleActionOverrides:
                - Name: SQLi_QUERYARGUMENTS
                  ActionToUse:
                    Block:
                      CustomResponse:
                        ResponseCode: 403
                        CustomResponseBodyKey: SecurityViolationError
                - Name: SQLi_BODY
                  ActionToUse:
                    Block:
                      CustomResponse:
                        ResponseCode: 403
                        CustomResponseBodyKey: SecurityViolationError
                - Name: SQLi_COOKIE
                  ActionToUse:
                    Block:
                      CustomResponse:
                        ResponseCode: 403
                        CustomResponseBodyKey: SecurityViolationError
                - Name: SQLiExtendedPatterns_QUERYARGUMENTS
                  ActionToUse:
                    Block:
                      CustomResponse:
                        ResponseCode: 403
                        CustomResponseBodyKey: SecurityViolationError
                - Name: SQLiExtendedPatterns_BODY
                  ActionToUse:
                    Block:
                      CustomResponse:
                        ResponseCode: 403
                        CustomResponseBodyKey: SecurityViolationError

已验证通过标签匹配的方式可以生效(需添加额外规则),但希望通过动作覆盖实现以避免额外成本。

核心结论

直接通过RuleActionOverrides为托管规则配置带自定义响应的Block动作目前AWS WAF不支持,这是配置无效的根本原因。

原因分析

  1. 功能限制:AWS WAF的RuleActionOverrides仅支持修改动作类型(如将Block改为Count,或Count改为Block),不支持在动作中附加自定义响应、自定义状态码等扩展配置。
  2. 文档缺陷:CloudFormation官方文档的属性定义看起来允许该配置,但未明确标注这一功能限制,导致出现语法合法但功能不生效的情况。

当前可行方案(标签匹配法)

这是AWS WAF当前支持自定义响应的唯一合规路径,虽然会增加规则数量,但能实现需求,配置示例如下:

Resources:
  Waf:
    Type: AWS::WAFv2::WebACL
    Properties:
      Scope: CLOUDFRONT
      DefaultAction:
        Allow: {} # Allow for requests that don't match any rules
      CustomResponseBodies:
        SecurityViolationError:
          ContentType: TEXT_PLAIN
          Content: Request blocked due to security concerns as it was detected as malicious.
      Rules:
        - Priority: 0
          Name: LabelSqlInjection
          OverrideAction:
            Count: {}
          Statement:
            ManagedRuleGroupStatement:
              VendorName: AWS
              Name: AWSManagedRulesSQLiRuleSet
              Version: Version_2.0
        - Priority: 1
          Name: BlockSecurityViolationError
          Statement:
            LabelMatchStatement:
              Scope: NAMESPACE
              Key: "awswaf:managed:aws:sql-database:"
          Action:
            Block:
              CustomResponse:
                ResponseCode: 403
                CustomResponseBodyKey: SecurityViolationError

疑问解答

  1. 是否遗漏配置? 没有,你的配置完全符合文档语法,问题出在AWS WAF的功能限制上。
  2. 能否通过动作覆盖实现自定义响应? 目前不能,该功能未开放。
  3. 官方文档是否存在缺失? 是的,文档未明确说明RuleActionOverrides不支持自定义响应配置,存在描述不清晰的问题。

内容的提问来源于stack exchange,提问作者Yves M.

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 03:35:56