tencent cloud

Web Application Firewall

Whitelist Sensitive Data Rule

Download
フォーカスモード
フォントサイズ
最終更新日: 2026-08-03 15:53:20
AI翻訳
After enabling the sensitive data allowlist rule, you can configure a sensitive data allowlist to exclude interfaces or fields that legitimately need to transmit sensitive information from sensitive detection. This feature supports adding an entire API to the allowlist (neither its requests nor responses are detected thereafter), or skipping detection for specified sensitive types on specified fields only. The system provides no built-in rules for sensitive data allowlisting; you must add custom rules. These rules have higher priority than all sensitive detection rules (including both built-in and custom ones): During detection, the system first checks whether an allowlist rule is matched. If matched, detection is skipped; if not, the normal sensitive detection process is executed.

Adding Custom Rule

After the sensitive data allowlist rule is enabled, you can customize whitelist sensitive data based on your business scenarios.
Note:
A maximum of 20 whitelist sensitive data rules can be manually added to a single domain.
2. In the Add Rule window, configure the following parameters and click OK to create the rule.
3. After you add a rule, you can edit or delete the corresponding rule.
Configuration Item Description
Rule name: Supports custom input, must be unique, and cannot exceed 128 characters.
Rule description: Optional. The description of the rule.
Whitelist Objects
Custom: When you select manual entry, you can configure the detection path scope. After configuration, all API assets under the specified path are detected. The detection scope can be matched using four logical operators: Belong to, Include, Start with and End with.
Select assets from existing API assets: Select discovered API assets from the asset list in the shuttle box. The feature supports sorting by the number of calls in the last 30 days and filtering by data Tags.
All APIs under the current domain name: When you select a domain, you do not need to select an API name below. All API assets under that domain are detected.
Whitelist Mode
Whitelist Entire API: After you enable this option, the system no longer performs sensitive data detection on all requests and response data for this API. In the asset list, the sensitive data types for this API are no longer displayed, and no risk events related to sensitive data are generated.
Whitelist Specified Field: Detection for specified sensitive types is skipped only for the specified fields. Detection for other fields and sensitive types remains unaffected.
Whitelist Field: This configuration is required when you select Whitelist Specified Field for Whitelist Mode. You must add at least one allowlisted field, and you can add up to 20.
Field Type: Supports QUERY, BODY, HEADERS, COOKIE, and Response.
Field Name: The maximum length is 64 characters.
Sensitive Data Type: Select multiple types from the system's built-in sensitive data types. You must configure the field name (parameter name) and the sensitive data type separately.
On/Off: Controls whether to enable or disable this rule. The default setting is On.

ヘルプとサポート

この記事はお役に立ちましたか?

フィードバック