An engine-decision laboratory
The runner uses Coraza 3.8.0 as a Go library and creates in-memory transactions. Original rules look for the harmless markers lab-marker and lab-second. It loads no CRS, opens no HTTP server and sends no attack traffic. The objective is to observe scope, phases and decisions with known data. A 403 interruption indicates what the engine asks the connector to do. To claim actual blocking in an architecture, verify that the connector enforces the decision and does not forward the request to the backend.
Build a false-positive hypothesis
The initial example sends comment=lab-marker as form data. Rule 1001 inspects ARGS and requests 403. In the fictional case the comment is legitimate and the approved exception is narrow: only that field, in that rule, on POST /reconciliation. Write this hypothesis before editing configuration. It defines both the case that should pass and controls that must keep matching. Also identify who approved the scope, which functional contract justifies it and which application change should trigger review of the need.
Observe the exception boundaries
The runtime exclusion combines path and method in phase 1 and removes ARGS:comment from rule 1001 for that transaction. The approved case stops interrupting. The runner then confirms four boundaries: account still matches; comment still matches at /other; PUT does not benefit from the exception; and lab-second in comment still matches independent rule 1002, which requests 409. Status 409 was chosen for the exercise and does not demonstrate a business conflict. The matrix shows that a field excluded from one rule remains available to other rules.
Compare configuration and per-request decisions
A separate experiment applies SecRuleUpdateTargetById to rule 1001 after it is defined, removing comment from its targets. The marker in that field also stops interrupting at /other. This directive does not contain the operation condition of the earlier runtime exclusion. The comparison makes the difference visible between changing targets in the configuration context and doing so only when a request meets conditions. Use the mechanism matching the demonstrated need, keep adaptations separate from the distributed ruleset and verify effective scope after an update.
Phase and position are part of the rule
The runner deliberately places the exclusion after rule 1001, both in phase 2. Interruption still occurs: the late change does not undo the decision already made. In another test, a rule with ID 9000 in phase 1 is observed before a rule with ID 200 in phase 2, even though it appears later in the text. Changing IDs therefore does not automatically correct order. For Coraza diagnosis, reconstruct phase and compilation order. Do not transfer AWS WAF numeric priority directly to these SecLang identifiers.
Accept the correction with a matrix
In a fictional reconciliation portal, the team restores comment entry but the account test also stops matching. The change still does not meet approved scope. Correct the exclusion or apply planned recovery, then rerun positive and negative tests. Retain configuration, version, synthetic inputs and results by rule. The summary is to assess an exception by what it restores and what it preserves. A functional 200 or absence of interruption alone does not demonstrate that remaining coverage survived the correction.
# Original local lab, not a production ruleset
# Rule 1001: ARGS contains lab-marker -> interruption 403
# Runtime exception: POST /reconciliation; rule 1001; ARGS:comment
# Matrix: comment passes, account still matches, /other still matches
# PUT still matches; rule 1002 still inspects commentFictional case: the legitimate comment passes, account remains inspected, PUT and /other retain the control, and a second rule can still match the same field.
Common pitfalls
Excluding an entire rule to correct one field, placing an exclusion after blocking, or using SecLang IDs as another product’s numeric priorities.
Related topics: Order, actions, and overrides · Parsing and inspection limits · Tuning and false positives
A useful regression demonstrates the authorized passing case and the fields, rules and operations that remain inspected.
Reference: Coraza SecLang actions · BigSavant WAF 2026-09; selected AWS WAF and OWASP CRS operational concepts