Good news! Another common reason for having to run relayd or nginx in front of OpenBSD httpd(8) has been eliminated.
#OpenBSD httpd(8) now supports new block and drop rules for filtering HTTP requests based on header values!
rsadowski@ modified src/usr.sbin/httpd/*: httpd: add header block/drop rules for request filtering
With this incoming requests can also be rejected based on the value of a request header. Valid options are:
header block name value code [arg]
Close the connection with an error response when a request header matches. Both name and value are shell-style patterns and are matched case-insensitively against the header name and value. code must be a valid HTTP status code. For codes in the 3xx range, arg is required and sent as the "Location" header. It must start with "http://" or "https://". For all other codes, arg is optional and used as the log message identifying the rule.header drop name value
Silently close the connection without sending a response
when a request header matches, using the same pattern rules as block.Based on a diff from Purple Rain from SecBSD, who wrote a initial version to block Ai- and other Scraper. Also requested and tested by Mischa.
Tested by Purple Rain, Mischa and others, thanks
Feedback by Lloyd, Christian Schulte, thanks
OK kirill@
Context (and configuration examples) can be found in the initial discussion on tech@: https://marc.info/?l=openbsd-tech&m=178999929723078&w=2
This follows support added for custom HTTP response headers back in July.