diff --git a/plugin.yaml b/plugin.yaml new file mode 100644 index 0000000..006bbb1 --- /dev/null +++ b/plugin.yaml @@ -0,0 +1,51 @@ +# OWASP CRS Plugin Descriptor +# See https://github.com/coreruleset/plugin-registry for the schema definition. + +schema_version: 1 + +plugin: + name: "template-plugin" + description: "Reference template plugin illustrating the OWASP CRS plugin mechanism." + long_description: | + The reference implementation of the OWASP CRS plugin structure. It is meant + to be copied and adapted as the starting point for new plugins, and it + documents the plugin file layout (-config.conf, -before.conf, -after.conf), + the mandatory enable/disable control rule, and the include order plugins + run in relative to the core rule set. + type: "official" + category: "utility" + status: "tested" + license: "Apache-2.0" + authors: + - name: "OWASP CRS Team" + url: "https://coreruleset.org" + repository: "https://github.com/coreruleset/template-plugin" + keywords: + - "template" + - "example" + - "starter" + - "reference" + +rule_id_range: + start: 9500000 + end: 9500999 + +compatibility: + crs_version: ">=4.0.0" + # engines is spelled out here, even though the template supports all three, + # to showcase the field for authors copying this file. A real plugin that + # truly supports every engine should omit `engines` instead: per + # docs/plugin-descriptor-schema.md, an omitted field already means "all". + engines: + - "modsecurity2" + - "modsecurity3" + - "coraza" + +configuration: + file: "plugins/template-config.conf" + variables: + - name: "tx.template-plugin_enabled" + type: "boolean" + default: 1 + description: "Enables or disables the template plugin (0 to disable)." + required: false