From fd058964faf00fcb4f4fc9eb080c7a973166e2da Mon Sep 17 00:00:00 2001 From: Xe Iaso Date: Mon, 28 Apr 2025 13:05:46 -0400 Subject: [PATCH] feat(data/apps): add API route allow rule for non-HEAD/GET Signed-off-by: Xe Iaso --- data/apps/allow-api-routes.yaml | 6 ++++++ 1 file changed, 6 insertions(+) create mode 100644 data/apps/allow-api-routes.yaml diff --git a/data/apps/allow-api-routes.yaml b/data/apps/allow-api-routes.yaml new file mode 100644 index 00000000..0cc3e3bf --- /dev/null +++ b/data/apps/allow-api-routes.yaml @@ -0,0 +1,6 @@ +- name: allow-api-routes + action: ALLOW + expression: + all: + - '!(method == "HEAD" || method == "GET")' + - path.startsWith("/api/") \ No newline at end of file