You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在AWS CDK WAF中禁用NonBrowserUserAgent规则?

解决AWS CDK默认WAF规则拦截非浏览器客户端请求的问题

问题描述

使用AWS CDK的WafwebaclToApiGateway构造配置WAF时,默认集成的AWS托管规则集中包含SignalNonBrowserUserAgent规则,该规则会拦截所有带有非浏览器标识的请求,导致应用、Postman、Python Requests等非浏览器客户端无法正常调用API接口,排查耗时数日才解决,现将配置及解决方案记录如下。

初始WAF配置代码

from aws_solutions_constructs.aws_wafwebacl_apigateway import WafwebaclToApiGateway
my_waf = WafwebaclToApiGateway(scope, waf_id, existing_api_gateway_interface=gateway)

解决方案

方案1:排除默认规则集中的SignalNonBrowserUserAgent规则

通过构造参数指定webacl_props,覆盖默认托管规则集配置,排除目标规则,保留其他安全防护逻辑:

from aws_solutions_constructs.aws_wafwebacl_apigateway import WafwebaclToApiGateway
from aws_cdk import aws_wafv2 as wafv2

my_waf = WafwebaclToApiGateway(
    scope, 
    waf_id, 
    existing_api_gateway_interface=gateway,
    webacl_props={
        "rules": [
            wafv2.CfnWebACL.RuleProperty(
                name="AWSManagedRulesCommonRuleSet",
                priority=0,
                statement=wafv2.CfnWebACL.StatementProperty(
                    managed_rule_group_statement=wafv2.CfnWebACL.ManagedRuleGroupStatementProperty(
                        name="AWSManagedRulesCommonRuleSet",
                        vendor_name="AWS",
                        # 排除拦截非浏览器请求的规则
                        excluded_rules=[
                            wafv2.CfnWebACL.ExcludedRuleProperty(name="SignalNonBrowserUserAgent")
                        ]
                    )
                ),
                override_action=wafv2.CfnWebACL.OverrideActionProperty(none={}),
                visibility_config=wafv2.CfnWebACL.VisibilityConfigProperty(
                    cloud_watch_metrics_enabled=True,
                    metric_name="AWSManagedRulesCommonRuleSet",
                    sampled_requests_enabled=True
                )
            )
        ]
    }
)

方案2:自定义规则允许特定非浏览器User-Agent

若需兼顾安全与业务需求,可添加优先级更高的允许规则,仅放行指定的合法非浏览器客户端请求:

from aws_solutions_constructs.aws_wafwebacl_apigateway import WafwebaclToApiGateway
from aws_cdk import aws_wafv2 as wafv2

my_waf = WafwebaclToApiGateway(
    scope, 
    waf_id, 
    existing_api_gateway_interface=gateway,
    webacl_props={
        "rules": [
            # 优先级1:放行指定的非浏览器客户端
            wafv2.CfnWebACL.RuleProperty(
                name="AllowApprovedNonBrowserAgents",
                priority=1,
                statement=wafv2.CfnWebACL.StatementProperty(
                    or_statement=wafv2.CfnWebACL.OrStatementProperty(
                        statements=[
                            # 允许Postman请求
                            wafv2.CfnWebACL.StatementProperty(
                                byte_match_statement=wafv2.CfnWebACL.ByteMatchStatementProperty(
                                    field_to_match=wafv2.CfnWebACL.FieldToMatchProperty(
                                        single_header={"Name": "User-Agent"}
                                    ),
                                    positional_constraint="CONTAINS",
                                    search_string="PostmanRuntime",
                                    text_transformations=[
                                        wafv2.CfnWebACL.TextTransformationProperty(
                                            priority=0,
                                            type="LOWERCASE"
                                        )
                                    ]
                                )
                            ),
                            # 允许Python Requests请求
                            wafv2.CfnWebACL.StatementProperty(
                                byte_match_statement=wafv2.CfnWebACL.ByteMatchStatementProperty(
                                    field_to_match=wafv2.CfnWebACL.FieldToMatchProperty(
                                        single_header={"Name": "User-Agent"}
                                    ),
                                    positional_constraint="CONTAINS",
                                    search_string="python-requests",
                                    text_transformations=[
                                        wafv2.CfnWebACL.TextTransformationProperty(
                                            priority=0,
                                            type="LOWERCASE"
                                        )
                                    ]
                                )
                            )
                        ]
                    )
                ),
                action=wafv2.CfnWebACL.RuleActionProperty(allow={}),
                visibility_config=wafv2.CfnWebACL.VisibilityConfigProperty(
                    cloud_watch_metrics_enabled=True,
                    metric_name="AllowApprovedNonBrowserAgents",
                    sampled_requests_enabled=True
                )
            ),
            # 优先级2:保留默认安全规则集
            wafv2.CfnWebACL.RuleProperty(
                name="AWSManagedRulesCommonRuleSet",
                priority=2,
                statement=wafv2.CfnWebACL.StatementProperty(
                    managed_rule_group_statement=wafv2.CfnWebACL.ManagedRuleGroupStatementProperty(
                        name="AWSManagedRulesCommonRuleSet",
                        vendor_name="AWS"
                    )
                ),
                override_action=wafv2.CfnWebACL.OverrideActionProperty(none={}),
                visibility_config=wafv2.CfnWebACL.VisibilityConfigProperty(
                    cloud_watch_metrics_enabled=True,
                    metric_name="AWSManagedRulesCommonRuleSet",
                    sampled_requests_enabled=True
                )
            )
        ]
    }
)

说明

  • 方案1适合需要完全放行所有非浏览器客户端请求的场景;
  • 方案2更安全,仅放行指定合法客户端,平衡业务需求与安全防护。

内容的提问来源于stack exchange,提问作者RooterTooter

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 07:53:17