tencent cloud

Web Application Firewall

Whitelist Sensitive Data Rule

Baixar
Modo Foco
Tamanho da Fonte
Última atualização: 2026-09-16 11:05:43
Traduzido e Verificado por IA
When sensitive data in normal business traffic is mistakenly identified as risky by sensitive content detection rules, you can configure a sensitive data allowlist to exclude the corresponding API or field from sensitive content detection. After the field is added to the allowlist, it no longer triggers sensitive data statistics or alarms.
Sensitive data allowlisting supports two granularities: allowlisting an entire API (neither its requests nor responses are detected), or skipping detection of specified sensitive types for specified fields only. There are no built-in sensitive data allowlist rules, so you need to add them manually. These rules take precedence over all sensitive content detection rules (including built-in and custom rules). During detection, the system first checks whether a request matches an allowlist rule. If it does, detection is skipped. If it does not, the normal sensitive content detection process is performed.

Adding Custom Rule

After the sensitive data allowlist rule is enabled, you can customize whitelist sensitive data based on your business scenarios.
Note:
A maximum of 20 whitelist sensitive data rules can be manually added to a single domain.
An allowlist rule takes effect immediately after it is saved. APIs or fields that hit the rule will immediately skip sensitive content detection.
Allowlisting takes effect only on subsequent traffic. Historical sensitive events that have already been generated are not processed retroactively.
2. In the Add Rule window, configure the following parameters and click OK to create the rule.
3. After you add a rule, you can edit or delete the corresponding rule.
Configuration Item Description
Rule name: Supports custom input, must be unique, and cannot exceed 128 characters.
Rule description: Optional. The description of the rule.
Whitelist Objects
Custom: When you select manual entry, you can configure the detection path scope. After configuration, all API assets under the specified path are detected. The detection scope can be matched using four logical operators: Belong to, Include, Start with and End with.
Select assets from existing API assets: Select discovered API assets from the asset list in the shuttle box. The feature supports sorting by the number of calls in the last 30 days and filtering by data Tags.
All APIs under the current domain name: When you select a domain, you do not need to select an API name below. All API assets under that domain are detected.
Whitelist Mode
Whitelist Entire API: After you enable this option, the system no longer performs sensitive data detection on all requests and response data for this API. In the asset list, the sensitive data types for this API are no longer displayed, and no risk events related to sensitive data are generated.
Whitelist Specified Field: Detection for specified sensitive types is skipped only for the specified fields. Detection for other fields and sensitive types remains unaffected.
Whitelist Field: This configuration is required when you select Whitelist Specified Field for Whitelist Mode. You must add at least one allowlisted field, and you can add up to 20.
Field Type: Supports GET, POST, Header, Cookie, and Response.
Field Name: The maximum length is 64 characters.
Sensitive Data Type: Select multiple types from the system's built-in sensitive data types. You must configure the field name (parameter name) and the sensitive data type separately.
On/Off: Controls whether to enable or disable this rule. The default setting is On.



Ajuda e Suporte

Esta página foi útil?

comentários