Akamai API Security Security policy: Conditions and exceptions API

Manage the attack groups and rules that you're currently evaluating for your security policies.

OpenAPI Specification

akamai-api-security-security-policy-conditions-and-exceptions-api-openapi.yml Raw ↑
openapi: 3.0.0
info:
  description: 'Manage your configurations for Kona Site Defender,

    Web Application Protector, and Client Reputation.

    '
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0.html
  title: 'Akamai: Application Security Activation history Security policy: Conditions and exceptions API'
  version: v1
servers:
- url: https://{hostname}/appsec/v1
tags:
- description: 'Manage the attack groups and rules that you''re currently evaluating

    for your security policies.'
  name: 'Security policy: Conditions and exceptions'
paths:
  /configs/{configId}/versions/{versionNumber}/security-policies/{policyId}/eval-groups/{attackGroupId}/condition-exception:
    parameters:
    - description: A unique identifier for each configuration.
      example: '{{configId}}'
      in: path
      name: configId
      required: true
      schema:
        example: 77653
        format: int64
        type: integer
      x-akamai:
        file-path: parameters/config-id-path.yaml
    - description: A unique identifier for each version of a configuration.
      example: '{{versionNumber}}'
      in: path
      name: versionNumber
      required: true
      schema:
        example: 25
        type: integer
      x-akamai:
        file-path: parameters/version-number-path.yaml
    - description: A unique identifier for a security policy.
      example: '{{policyId}}'
      in: path
      name: policyId
      required: true
      schema:
        example: boBF_19288
        type: string
      x-akamai:
        file-path: parameters/policy-id-path.yaml
    - description: A unique identifier for each attack group.
      example: '{{attackGroupId}}'
      in: path
      name: attackGroupId
      required: true
      schema:
        example: CMD
        type: string
      x-akamai:
        file-path: parameters/attack-group-id-path.yaml
    x-akamai:
      file-path: paths/policy-eval-group-condition-exception.yaml
      path-info: /configs/{configId}/versions/{versionNumber}/security-policies/{policyId}/eval-groups/{attackGroupId}/condition-exception
    get:
      description: List an attack group's exceptions. _Products:_ All.
      externalDocs:
        description: See documentation for this operation in Akamai's Application Security API
        url: https://techdocs.akamai.com/application-security/reference/get-eval-group-condition-exception
      operationId: get-eval-group-condition-exception
      parameters:
      - description: For customers who manage more than one account, this [runs the operation from another account](https://techdocs.akamai.com/developer/docs/manage-many-accounts-with-one-api-client). The Identity and Access Management API provides a [list of available account switch keys](https://techdocs.akamai.com/iam-api/reference/get-client-account-switch-keys).
        example: '{{accountSwitchKey}}'
        in: query
        name: accountSwitchKey
        required: false
        schema:
          example: 1-5C0YLB:1-8BYUX
          type: string
      responses:
        '200':
          content:
            application/json:
              example:
                advancedExceptions:
                  conditionOperator: AND
                  conditions:
                  - filenames:
                    - '*.aspx'
                    - '*.js'
                    positiveMatch: true
                    type: filenameMatch
                  - paths:
                    - /catalog
                    positiveMatch: true
                    type: pathMatch
                  - clientLists:
                    - 88330_TESTIP1
                    positiveMatch: true
                    type: clientListMatch
                    useHeaders: true
                  headerCookieOrParamValues:
                  - valueWildcard: true
                    values:
                    - header1
                    - cookie1
                    - param1
                  specificHeaderCookieOrParamNameValue:
                  - namesValues:
                    - names:
                      - header1
                      values:
                      - value1
                    selector: REQUEST_HEADERS
                    wildcard: true
                  - namesValues:
                    - names:
                      - param-name
                      values:
                      - param-value
                    selector: ARGS
                    wildcard: true
                  - namesValues:
                    - names:
                      - json-param1
                      values:
                      - json-value1
                    selector: JSON_PAIRS
                    wildcard: true
                  - namesValues:
                    - names:
                      - cookie-name
                      values:
                      - cookie1
                    selector: REQUEST_COOKIES
                    wildcard: true
                  specificHeaderCookieParamXmlOrJsonNames:
                  - criteria:
                    - hostnames:
                      - www.host.com
                      paths:
                      - /*
                    selector: REQUEST_HEADERS_NAMES
                    wildcard: true
                  - criteria:
                    - hostnames:
                      - ALL
                      names:
                      - header1
                      paths:
                      - /orders
                    names:
                    - header2
                    selector: REQUEST_HEADERS
                    wildcard: false
                  - criteria:
                    - hostnames:
                      - ALL
                      paths:
                      - /*
                    selector: ARGS_NAMES
                    wildcard: true
                  - names:
                    - param-name
                    selector: ARGS
                    wildcard: true
                  - names:
                    - '*'
                    selector: JSON_NAMES
                    wildcard: true
                  - names:
                    - json1
                    selector: JSON_PAIRS
                    wildcard: true
                  - names:
                    - connect.sid
                    selector: REQUEST_COOKIES_NAMES
                    wildcard: false
                  - names:
                    - cookie1
                    - cookie2
                    selector: REQUEST_COOKIES
                    wildcard: true
                  - selector: REQUEST_BODY
                    wildcard: true
                  - selector: REQBODY_PROCESSOR_ERROR
                    wildcard: true
                  - selector: FILES_NAMES
                    wildcard: true
                  - selector: REQUEST_PROTOCOL
                    wildcard: true
                  - selector: REQUEST_METHOD
                    wildcard: true
                  - selector: REQUEST_URI
                    wildcard: true
                  - selector: QUERY_STRING
                    wildcard: true
                  - selector: REQUEST_FILENAME
                    wildcard: true
                  - selector: REQUEST_PATH_SEGMENT
                    wildcard: true
              schema:
                additionalProperties: false
                description: The GET Response JSON for conditions and exceptions.
                properties:
                  advancedExceptions:
                    additionalProperties: false
                    description: Describes the advanced exception members that allow you to conditionally exclude requests from inspection. This is only available for attack groups and when the advanced exception feature is enabled.
                    properties:
                      conditionOperator:
                        description: Use `OR` to match any condition, or `AND` to match on all conditions.
                        enum:
                        - OR
                        - AND
                        type: string
                      conditions:
                        description: The list of match conditions.
                        items:
                          additionalProperties: false
                          description: Describes what conditions can be set for an action to occur.
                          properties:
                            caseSensitive:
                              description: Whether to consider the case-sensitivity of the provided query parameter `value`. This only applies to the `uriQueryMatch` condition `type`.
                              type: boolean
                            clientLists:
                              description: The clientLists that trigger the condition. This only applies to the `clientListMatch` condition `type`.
                              items:
                                type: string
                              minItems: 0
                              type: array
                            extensions:
                              description: The file extensions that trigger the condition. This only applies to the `extensionMatch` condition `type`.
                              items:
                                type: string
                              type: array
                            filenames:
                              description: The filenames that trigger the condition. This only applies to the `filenameMatch` condition `type`.
                              items:
                                type: string
                              type: array
                            header:
                              description: The HTTP header that triggers the condition. This only applies to the `requestHeaderMatch` condition `type`.
                              type: string
                            hosts:
                              description: The hostnames that trigger the condition. This only applies to the `hostMatch` condition `type`.
                              items:
                                type: string
                              type: array
                            ips:
                              description: The IPs that trigger the condition. This only applies to the `ipMatch` condition `type`.
                              items:
                                type: string
                              type: array
                            methods:
                              description: The HTTP request methods that trigger the condition. The possible values are `GET`, `POST`, `HEAD`, `PUT`, `DELETE`, `OPTIONS`, `TRACE`, `CONNECT` and `PATCH`. This only applies to the `requestMethodMatch` condition `type`.
                              items:
                                enum:
                                - GET
                                - POST
                                - HEAD
                                - PUT
                                - DELETE
                                - OPTIONS
                                - TRACE
                                - CONNECT
                                - PATCH
                                type: string
                              type: array
                            name:
                              description: The query parameter name that triggers the condition. This only applies to the `uriQueryMatch` condition `type`.
                              type: string
                            nameCase:
                              description: Whether to consider the case-sensitivity of the provided query parameter `name`. This only applies to the `uriQueryMatch` condition `type`.
                              type: boolean
                            paths:
                              description: The paths that trigger the condition. This only applies to the  `pathMatch` condition `type`.
                              items:
                                type: string
                              type: array
                            positiveMatch:
                              description: Whether the condition should trigger on a match (`true`) or a lack of match (`false`).
                              type: boolean
                            type:
                              description: The condition type to match on. See [Export condition type values](https://techdocs.akamai.com/application-security/reference/etval).
                              enum:
                              - hostMatch
                              - pathMatch
                              - filenameMatch
                              - extensionMatch
                              - uriQueryMatch
                              - ipMatch
                              - requestMethodMatch
                              - requestHeaderMatch
                              - clientListMatch
                              type: string
                            useHeaders:
                              description: Whether the condition should include `X-Forwarded-For` (XFF) header. This applies to the `ipMatch` and `clientListMatch` condition `type`.
                              type: boolean
                            value:
                              description: The query parameter value if the condition `type` is `uriQueryMatch` and header value if the condition `type` is `requestHeaderMatch`. This only applies when the condition `type` is `uriQueryMatch` or `requestHeaderMatch`.
                              type: string
                            valueCase:
                              description: Whether to consider the case-sensitivity of the provided header `value`. This only applies to the `requestHeaderMatch` condition `type`.
                              type: boolean
                            valueWildcard:
                              description: Whether the provided header `value` is a wildcard. This only applies to the `requestHeaderMatch` condition `type`.
                              type: boolean
                            wildcard:
                              description: Whether the provided query parameter `value` is a wildcard. This only applies to the `uriQueryMatch` condition `type`.
                              type: boolean
                          required:
                          - type
                          - positiveMatch
                          type: object
                          x-akamai:
                            file-path: schemas/condition.yaml
                        type: array
                      headerCookieOrParamValues:
                        description: The list of excepted values in headers, cookies, or query parameters.
                        items:
                          additionalProperties: false
                          properties:
                            criteria:
                              description: A list of criteria to limit the scope of this exception.
                              items:
                                additionalProperties: false
                                description: The hostname and path criteria to limit the scope of exception.
                                properties:
                                  hostnames:
                                    description: The list of excepted hostnames.
                                    items:
                                      type: string
                                    type: array
                                  names:
                                    description: The list of excepted names.
                                    items:
                                      type: string
                                    type: array
                                  paths:
                                    description: The list of excepted paths.
                                    items:
                                      type: string
                                    type: array
                                  values:
                                    description: The list of excepted values.
                                    items:
                                      type: string
                                    type: array
                                required:
                                - paths
                                - names
                                - values
                                type: object
                                x-akamai:
                                  file-path: schemas/criteria.yaml
                              type: array
                            valueWildcard:
                              default: false
                              description: Whether the provided header `name` is a wildcard.
                              type: boolean
                            values:
                              description: The list of request attribute names.
                              items:
                                type: string
                              type: array
                          required:
                          - values
                          type: object
                        type: array
                      specificHeaderCookieOrParamNameValue:
                        description: Contains details about the excepted name-value pairs in a request.
                        items:
                          additionalProperties: false
                          properties:
                            criteria:
                              description: A list of criteria to limit the scope of this exception.
                              items:
                                additionalProperties: false
                                description: The hostname and path criteria to limit the scope of exception.
                                properties:
                                  hostnames:
                                    description: The list of excepted hostnames.
                                    items:
                                      type: string
                                    type: array
                                  names:
                                    description: The list of excepted names.
                                    items:
                                      type: string
                                    type: array
                                  paths:
                                    description: The list of excepted paths.
                                    items:
                                      type: string
                                    type: array
                                  values:
                                    description: The list of excepted values.
                                    items:
                                      type: string
                                    type: array
                                required:
                                - paths
                                - names
                                - values
                                type: object
                                x-akamai:
                                  file-path: schemas/criteria.yaml
                              type: array
                            namesValues:
                              description: A list of name-value pairs to except.
                              items:
                                additionalProperties: false
                                properties:
                                  names:
                                    description: The list of request attribute names.
                                    items:
                                      type: string
                                    type: array
                                  values:
                                    description: The list of request attribute values.
                                    items:
                                      type: string
                                    type: array
                                required:
                                - names
                                type: object
                              type: array
                            selector:
                              description: The request attribute to exclude from inspection. See [Exception selector values](https://techdocs.akamai.com/application-security/reference/exception-selector-values).
                              enum:
                              - REQUEST_COOKIES
                              - JSON_PAIRS
                              - XML_PAIRS
                              - ARGS
                              - REQUEST_HEADERS
                              type: string
                            wildcard:
                              default: false
                              description: Whether the provided header `name` is a wildcard.
                              type: boolean
                          required:
                          - namesValues
                          - selector
                          type: object
                        type: array
                      specificHeaderCookieParamXmlOrJsonNames:
                        description: Describes the advanced exception members that allow you to conditionally exclude requests from inspection. This is only available for attack groups and when the advanced exception feature is enabled.
                        items:
                          additionalProperties: false
                          properties:
                            criteria:
                              description: A list of criteria to limit the scope of this exception.
                              items:
                                additionalProperties: false
                                description: The hostname and path criteria to limit the scope of exception.
                                properties:
                                  hostnames:
                                    description: The list of excepted hostnames.
                                    items:
                                      type: string
                                    type: array
                                  names:
                                    description: The list of excepted names.
                                    items:
                                      type: string
                                    type: array
                                  paths:
                                    description: The list of excepted paths.
                                    items:
                                      type: string
                                    type: array
                                  values:
                                    description: The list of excepted values.
                                    items:
                                      type: string
                                    type: array
                                required:
                                - paths
                                - names
                                - values
                                type: object
                                x-akamai:
                                  file-path: schemas/criteria.yaml
                              type: array
                            names:
                              description: The list of request attribute names.
                              items:
                                type: string
                              type: array
                            selector:
                              description: The request attribute to exclude from inspection. See [Exception selector values](https://techdocs.akamai.com/application-security/reference/exception-selector-values).
                              enum:
                              - ARGS_NAMES
                              - ARGS
                              - REQUEST_HEADERS_NAMES
                              - REQUEST_HEADERS
                              - REQUEST_COOKIES_NAMES
                              - REQUEST_COOKIES
                              - JSON_NAMES
                              - JSON_PAIRS
                              - XML_PAIRS
                              - REQUEST_PROTOCOL
                              - REQUEST_METHOD
                              - REQUEST_URI
                              - QUERY_STRING
                              - REQUEST_FILENAME
                              - REQUEST_PATH_SEGMENT
                              - REQUEST_BODY
                              - REQBODY_PROCESSOR_ERROR
                              - FILES_NAMES
                              type: string
                            wildcard:
                              default: false
                              description: Whether the provided header `name` is a wildcard.
                              type: boolean
                          required:
                          - selector
                          type: object
                        type: array
                    type: object
                    x-akamai:
                      file-path: schemas/advanced-exception.yaml
                  conditions:
                    description: The conditions list for a rule.
                    items:
                      additionalProperties: false
                      description: Describes what conditions can be set for an action to occur.
                      properties:
                        caseSensitive:
                          description: Whether to consider the case-sensitivity of the provided query parameter `value`. This only applies to the `uriQueryMatch` condition `type`.
                          type: boolean
                        clientLists:
                          description: The clientLists that trigger the condition. This only applies to the `clientListMatch` condition `type`.
                          items:
                            type: string
                          minItems: 0
                          type: array
                        extensions:
                          description: The file extensions that trigger the condition. This only applies to the `extensionMatch` condition `type`.
                          items:
                            type: string
                          type: array
                        filenames:
                          description: The filenames that trigger the condition. This only applies to the `filenameMatch` condition `type`.
                          items:
                            type: string
                          type: array
                        header:
                          description: The HTTP header that triggers the condition. This only applies to the `requestHeaderMatch` condition `type`.
                          type: string
                        hosts:
                          description: The hostnames that trigger the condition. This only applies to the `hostMatch` condition `type`.
                          items:
                            type: string
                          type: array
                        ips:
                          description: The IPs that trigger the condition. This only applies to the `ipMatch` condition `type`.
                          items:
                            type: string
                          type: array
                        methods:
                          description: The HTTP request methods that trigger the condition. The possible values are `GET`, `POST`, `HEAD`, `PUT`, `DELETE`, `OPTIONS`, `TRACE`, `CONNECT` and `PATCH`. This only applies to the `requestMethodMatch` condition `type`.
                          items:
                            enum:
                            - GET
                            - POST
                            - HEAD
                            - PUT
                            - DELETE
                            - OPTIONS
                            - TRACE
                            - CONNECT
                            - PATCH
                            type: string
                          type: array
                        name:
                          description: The query parameter name that triggers the condition. This only applies to the `uriQueryMatch` condition `type`.
                          type: string
                        nameCase:
                          description: Whether to consider the case-sensitivity of the provided query parameter `name`. This only applies to the `uriQueryMatch` condition `type`.
                          type: boolean
                        paths:
                          description: The paths that trigger the condition. This only applies to the  `pathMatch` condition `type`.
                          items:
                            type: string
                          type: array
                        positiveMatch:
                          description: Whether the condition should trigger on a match (`true`) or a lack of match (`false`).
                          type: boolean
                        type:
                          description: The condition type to match on. See [Export condition type values](https://techdocs.akamai.com/application-security/reference/etval).
                          enum:
                          - hostMatch
                          - pathMatch
                          - filenameMatch
                          - extensionMatch
                          - uriQueryMatch
                          - ipMatch
                          - requestMethodMatch
                          - requestHeaderMatch
                          - clientListMatch
                          type: string
                        useHeaders:
                          description: Whether the condition should include `X-Forwarded-For` (XFF) header. This applies to the `ipMatch` and `clientListMatch` condition `type`.
                          type: boolean
                        value:
                          description: The query parameter value if the condition `type` is `uriQueryMatch` and header value if the condition `type` is `requestHeaderMatch`. This only applies when the condition `type` is `uriQueryMatch` or `requestHeaderMatch`.
                          type: string
                        valueCase:
                          description: Whether to consider the case-sensitivity of the provided header `value`. This only applies to the `requestHeaderMatch` condition `type`.
                          type: boolean
                        valueWildcard:
                          description: Whether the provided header `value` is a wildcard. This only applies to the `requestHeaderMatch` condition `type`.
                          type: boolean
                        wildcard:
                          description: Whether the provided query parameter `value` is a wildcard. This only applies to the `uriQueryMatch` condition `type`.
                          type: boolean
                      required:
                      - type
                      - positiveMatch
                      type: object
                      x-akamai:
                        file-path: schemas/condition.yaml
                    type: array
                  exception:
                    additionalProperties: false
                    description: Describes the exception members that allow you to conditionally exclude requests from inspection.
                    properties:
                      anyHeaderCookieOrParam:
                        description: The list of request attributes to treat as rule or attack group exceptions. The possible values are `REQUEST_COOKIES`, `JSON_PAIRS` for a JSON parameter, `XML_PAIRS` for an XML parameter, `ARGS` for a request parameter, and `REQUEST_HEADERS` for a request header. Use this option if you can't get an exhaustive list of elements to exclude or the list is too large. You can exclude several attributes.
                        items:
                          enum:
                          - REQUEST_COOKIES
                          - JSON_PAIRS
                          - XML_PAIRS
                          - ARGS
                          - REQUEST_HEADERS
                          type: string
                        type: array
                      headerCookieOrParamValues:
                

# --- truncated at 32 KB (227 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/akamai-api-security/refs/heads/main/openapi/akamai-api-security-security-policy-conditions-and-exceptions-api-openapi.yml