
software.amazon.awssdk.services.wafv2.model.XssMatchStatement Maven / Gradle / Ivy
/*
* Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.
*
* Licensed under the Apache License, Version 2.0 (the "License"). You may not use this file except in compliance with
* the License. A copy of the License is located at
*
* http://aws.amazon.com/apache2.0
*
* or in the "license" file accompanying this file. This file is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR
* CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions
* and limitations under the License.
*/
package software.amazon.awssdk.services.wafv2.model;
import java.io.Serializable;
import java.util.Arrays;
import java.util.Collection;
import java.util.Collections;
import java.util.List;
import java.util.Objects;
import java.util.Optional;
import java.util.function.BiConsumer;
import java.util.function.Consumer;
import java.util.function.Function;
import java.util.stream.Collectors;
import java.util.stream.Stream;
import software.amazon.awssdk.annotations.Generated;
import software.amazon.awssdk.core.SdkField;
import software.amazon.awssdk.core.SdkPojo;
import software.amazon.awssdk.core.protocol.MarshallLocation;
import software.amazon.awssdk.core.protocol.MarshallingType;
import software.amazon.awssdk.core.traits.ListTrait;
import software.amazon.awssdk.core.traits.LocationTrait;
import software.amazon.awssdk.core.util.DefaultSdkAutoConstructList;
import software.amazon.awssdk.core.util.SdkAutoConstructList;
import software.amazon.awssdk.utils.ToString;
import software.amazon.awssdk.utils.builder.CopyableBuilder;
import software.amazon.awssdk.utils.builder.ToCopyableBuilder;
/**
*
* A rule statement that inspects for cross-site scripting (XSS) attacks. In XSS attacks, the attacker uses
* vulnerabilities in a benign website as a vehicle to inject malicious client-site scripts into other legitimate web
* browsers.
*
*/
@Generated("software.amazon.awssdk:codegen")
public final class XssMatchStatement implements SdkPojo, Serializable,
ToCopyableBuilder {
private static final SdkField FIELD_TO_MATCH_FIELD = SdkField. builder(MarshallingType.SDK_POJO)
.memberName("FieldToMatch").getter(getter(XssMatchStatement::fieldToMatch)).setter(setter(Builder::fieldToMatch))
.constructor(FieldToMatch::builder)
.traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("FieldToMatch").build()).build();
private static final SdkField> TEXT_TRANSFORMATIONS_FIELD = SdkField
.> builder(MarshallingType.LIST)
.memberName("TextTransformations")
.getter(getter(XssMatchStatement::textTransformations))
.setter(setter(Builder::textTransformations))
.traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("TextTransformations").build(),
ListTrait
.builder()
.memberLocationName(null)
.memberFieldInfo(
SdkField. builder(MarshallingType.SDK_POJO)
.constructor(TextTransformation::builder)
.traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD)
.locationName("member").build()).build()).build()).build();
private static final List> SDK_FIELDS = Collections.unmodifiableList(Arrays.asList(FIELD_TO_MATCH_FIELD,
TEXT_TRANSFORMATIONS_FIELD));
private static final long serialVersionUID = 1L;
private final FieldToMatch fieldToMatch;
private final List textTransformations;
private XssMatchStatement(BuilderImpl builder) {
this.fieldToMatch = builder.fieldToMatch;
this.textTransformations = builder.textTransformations;
}
/**
*
* The part of the web request that you want WAF to inspect.
*
*
* @return The part of the web request that you want WAF to inspect.
*/
public final FieldToMatch fieldToMatch() {
return fieldToMatch;
}
/**
* For responses, this returns true if the service returned a value for the TextTransformations property. This DOES
* NOT check that the value is non-empty (for which, you should check the {@code isEmpty()} method on the property).
* This is useful because the SDK will never return a null collection or map, but you may need to differentiate
* between the service returning nothing (or null) and the service returning an empty collection or map. For
* requests, this returns true if a value for the property was specified in the request builder, and false if a
* value was not specified.
*/
public final boolean hasTextTransformations() {
return textTransformations != null && !(textTransformations instanceof SdkAutoConstructList);
}
/**
*
* Text transformations eliminate some of the unusual formatting that attackers use in web requests in an effort to
* bypass detection. Text transformations are used in rule match statements, to transform the
* FieldToMatch
request component before inspecting it, and they're used in rate-based rule statements,
* to transform request components before using them as custom aggregation keys. If you specify one or more
* transformations to apply, WAF performs all transformations on the specified content, starting from the lowest
* priority setting, and then uses the transformed component contents.
*
*
* Attempts to modify the collection returned by this method will result in an UnsupportedOperationException.
*
*
* This method will never return null. If you would like to know whether the service returned this field (so that
* you can differentiate between null and empty), you can use the {@link #hasTextTransformations} method.
*
*
* @return Text transformations eliminate some of the unusual formatting that attackers use in web requests in an
* effort to bypass detection. Text transformations are used in rule match statements, to transform the
* FieldToMatch
request component before inspecting it, and they're used in rate-based rule
* statements, to transform request components before using them as custom aggregation keys. If you specify
* one or more transformations to apply, WAF performs all transformations on the specified content, starting
* from the lowest priority setting, and then uses the transformed component contents.
*/
public final List textTransformations() {
return textTransformations;
}
@Override
public Builder toBuilder() {
return new BuilderImpl(this);
}
public static Builder builder() {
return new BuilderImpl();
}
public static Class extends Builder> serializableBuilderClass() {
return BuilderImpl.class;
}
@Override
public final int hashCode() {
int hashCode = 1;
hashCode = 31 * hashCode + Objects.hashCode(fieldToMatch());
hashCode = 31 * hashCode + Objects.hashCode(hasTextTransformations() ? textTransformations() : null);
return hashCode;
}
@Override
public final boolean equals(Object obj) {
return equalsBySdkFields(obj);
}
@Override
public final boolean equalsBySdkFields(Object obj) {
if (this == obj) {
return true;
}
if (obj == null) {
return false;
}
if (!(obj instanceof XssMatchStatement)) {
return false;
}
XssMatchStatement other = (XssMatchStatement) obj;
return Objects.equals(fieldToMatch(), other.fieldToMatch()) && hasTextTransformations() == other.hasTextTransformations()
&& Objects.equals(textTransformations(), other.textTransformations());
}
/**
* Returns a string representation of this object. This is useful for testing and debugging. Sensitive data will be
* redacted from this string using a placeholder value.
*/
@Override
public final String toString() {
return ToString.builder("XssMatchStatement").add("FieldToMatch", fieldToMatch())
.add("TextTransformations", hasTextTransformations() ? textTransformations() : null).build();
}
public final Optional getValueForField(String fieldName, Class clazz) {
switch (fieldName) {
case "FieldToMatch":
return Optional.ofNullable(clazz.cast(fieldToMatch()));
case "TextTransformations":
return Optional.ofNullable(clazz.cast(textTransformations()));
default:
return Optional.empty();
}
}
@Override
public final List> sdkFields() {
return SDK_FIELDS;
}
private static Function