I had a slightly amusing bug yesterday. Our web app has a feature where you invite by email. I got a bug report stating that “I can invite emails from my company but not my personal email”. How strange. The service does not have any such filtering.
As part of the invitation a REST request is sent to the server in the form of /api/users/{email} . It works locally, but in Azure the endpoint was sometimes blocked. I found that the Azure Web Application Firewall had blocked the request due to OWASP CRS rules: “URL file extension blocked by policy”.
Let’s take a step back and look at the mail addresses:
- Living in Sweden, a typical company address would be john@company.se
- A typical personal email would be jane@gmail.com
Why would the firewall only block the latter one? Remember that in Windows, .com files are executable and thus classified as dangerous. This of course has nothing to do with emails, but it is blocked by the default policy rules.
The personal vs company email was just an amusing interpretation of the situation :-)
And the solution? Instead of submitting the email as part of the URL, put it in the body or as a query parameter:
- ❌: /api/users/jane@gmail.com
- ✅: /api/users?email=jane@gmail.com
