ASM Bot Defense JS and CSP
Our company has issued a requirement for all applications to enable CSP (Content Security Policy). The problem is one of the first applications to enable this has Bot Defense enabled. Part of PBD is to inject a JAVA script inline which causes an issue with the page not loading per the CSP policy. We opened a support case and F5 level II and the ENE say they can't find a way to make these compatible and this is beyond the scope of Support i.e. engage Professional Services. I'm a long-time F5 user and so this was frustrating, to say the least.
Part of our CSP is our scripts have a nonce key generated. PBD script is not being delivered from our server (it's directly injected into the response), and it does not contain our nonce key. This means that the CSP will tell the browser to NOT allow the execution of that script thereby breaking the application.
Part of the CSP Rules
- The browser should accept any JS that is delivered as a file from 'self' which means it's delivered from our web server with a relative path
- The browser should accept any JS that is delivered to the browser with our nonce key (value in the header)
- All other JS should be ignored by the browser!
So, the only question that we really had for F5 is how do we make PBD JS work with a CSP? The CSP is set up in a basic way and is not customized to our application at all. It seems we either need to have this JS delivered by a file (not directly injected) or the F5 will need to pick up our nonce key and add it to that injection.
Has anyone come across this and what methods did you employ to resolve it, i.e. iRule or Traffic policy to set the nonce key on the JS, which is not super ideal?
Depending on when ASM/PBD fire, something similar to the following:
when HTTP_RESPONSE {
# Check if the response header contains a CSP
if {[HTTP::header exists "Content-Security-Policy"]} {
# Get the CSP header value
set csp [HTTP::header value "Content-Security-Policy"]
# Check if the CSP contains a nonce
if {[string first "nonce-" $csp] != -1} {
# Get the nonce value
set nonce [string range $csp [string first "nonce-" $csp] [string first ";" $csp]]
# Check if the response body contains a script tag
if {[string first "<script" [HTTP::payload]] != -1} {
# Add the nonce to the script tag
HTTP::payload replace [string first "<script" [HTTP::payload]] [string first ">" [HTTP::payload]] "<script nonce=\"$nonce\""
}
}
}
}