:source: fwebos_waf_cookie_security.py
:orphan:
.. fwebos_waf_cookie_security.py:
fwebos_waf_cookie_security.py -- Config FortiWeb Web Protection Cookie Security
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
.. versionadded:: 1.0.1
.. contents::
:local:
:depth: 1
Synopsis
--------
Config FortiWeb Web Protection Cookie Security
Requirements
------------
The below requirements are needed on the host that executes this module.
- ansible>=2.11
FortiWeb Version Compatibility
------------------------------
.. raw:: html
|
v7.0.x |
v7.2.x |
v7.4.x |
v7.6.x |
| fwebos_waf_cookie_security.py |
yes |
yes |
yes |
yes |
Parameters
----------
.. raw:: html
- body Possible parameters to go in the body for the request required: True
- name name type:string
maxLength:63
- cookie-security-exception-list cookie security exception list type:array
- id The number of the cookie security exception list
- cookie-name cookie name
- cookie-domain cookie domain
- cookie-path cookie path
- wildcard treat asterisk in cookie-name as wildcard
- security-mode security mode type:string choice:
no,
encrypted,
signed,
- action action type:string choice:
alert,
deny_no_log,
alert_deny,
remove_cookie,
block-period,
client-id-block-period,
- block-period action block period(1-3600) type:integer
maximum:3600
minimum:1
- severity High, Medium, Low or Informative type:string choice:
High,
Medium,
Low,
Info,
- trigger choose Email or syslog policy type:string
- cookie-replay-protection-type cookie replay protection type type:string choice:
no,
IP,
- max-age max-age(0-65535) type:integer
maximum:65535
minimum:0
- secure-cookie secure cookie type:string choice:
enable,
disable,
- http-only http only type:string choice:
enable,
disable,
- allow-suspicious-cookies allow suspicious cookies type:string choice:
Never,
Always,
Custom,
- allow-time allow date type:string
- mkey If present, objects will be filtered on property with this name type:string
- vdom Specify the Virtual Domain(s) from which results are returned or changes are applied to. If this parameter is not provided, the management VDOM will be used. If the admin does not have access to the VDOM, a permission error will be returned. The URL parameter is one of: vdom=root (Single VDOM) vdom=vdom1,vdom2 (Multiple VDOMs) vdom=* (All VDOMs) type:array
- clone_mkey Use *clone_mkey* to specify the ID for the new resource to be cloned. If *clone_mkey* is set, *mkey* must be provided which is cloned from. type:string
Examples
--------
.. code-block:: yaml+jinja
- name:
hosts: all
vars:
connection: httpapi
gather_facts: false
tasks:
- name: delete
fwebos_waf_cookie_security:
action: delete
vdom: root
name: test
- name: Create
fwebos_waf_cookie_security:
action: add
vdom: root
security_mode: encrypted
cookie_replay_protection_type: IP
allow_suspicious_cookies: Custom
allow_time_model: 2022-10-28T17:11:54.000Z
security_action: alert
severity: Medium
block_period: 600
max_age: 0
http_only: disable
name: test
trigger: test
allow_time: 2022/10/28
- name: edit
fwebos_waf_cookie_security:
action: edit
vdom: root
security_mode: encrypted
cookie_replay_protection_type: IP
allow_suspicious_cookies: Custom
allow_time_model: 2022-10-28T17:11:54.000Z
security_action: alert
severity: Medium
block_period: 600
max_age: 0
http_only: disable
name: test
trigger: test
allow_time: 2022/10/27
Return Values
-------------
Common return values are documented: https://docs.ansible.com/ansible/latest/reference_appendices/common_return_values.html#common-return-values, the following are the fields unique to this module:
.. raw:: html
- 200 : OK: Request returns successful
- 400 : Bad Request: Request cannot be processed by the API
- 401 : Not Authorized: Request without successful login session
- 403 : Forbidden: Request is missing CSRF token or administrator is missing access profile permissions.
- 404 : Resource Not Found: Unable to find the specified resource.
- 405 : Method Not Allowed: Specified HTTP method is not allowed for this resource.
- 413 : Request Entity Too Large: Request cannot be processed due to large entity
- 424 : Failed Dependency: Fail dependency can be duplicate resource, missing required parameter, missing required attribute, invalid attribute value
- 429 : Access temporarily blocked: Maximum failed authentications reached. The offended source is temporarily blocked for certain amount of time.
- 500 : Internal Server Error: Internal error when processing the request
For errorcode please check FortiWeb API errorcode at : https://documenter.getpostman.com/view/11233300/TVetbkaK#887b9eb4-7c13-4338-a8db-16cc117f0119
Status
------
- This module is not guaranteed to have a backwards compatible interface.
Authors
-------
- Jie Li
- Brad Zhang
.. hint::
If you notice any issues in this documentation, you can create a pull request to improve it.