This message was deleted.
# citrix-netscaler
s
This message was deleted.
r
LOL, I was going to ask that
k
It was bit of a surprise ChatGPT could write those expressions, but well... pretty handy also.
r
It helps me when I am stuck in powershell aslo.
k
it does
amazing thing
a bit scary too though
r
One thing I learned, If you take the error and put it back in ChatGPT it will correct the script
k
yeah, doing that as we speak
gets even more scarier
r
I said before, it my personal virtual @Guy Leech lol
k
not a native English-speaker, so this brings in an extra layer of challenge
r
no worries.
Let me know if I said something that was confusing and I can explain it better
k
(!HTTP.REQ.HEADER("hash").EXISTS) || (HTTP.REQ.HEADER("hash").EXISTS && (!HTTP.REQ.HEADER("authkey").EXISTS&& !HTTP.REQ.HEADER("token").EXISTS))
that seems to work
two checks 1. the "hash" needs to be always present
2. if the hash is present, then either "authkey" or "token" needs to be present also
that passes my expression evaluator
l
Kari:
I don't see how your last expression would be ok though --> depending if it can validate as true if hash is not present. You say it always has to be present so the first || is weird to me ?
k
uhm... (!HTTP.REQ.HEADER("hash").EXISTS) || (HTTP.REQ.HEADER("hash").EXISTS && (!HTTP.REQ.HEADER("authkey").EXISTS&& !HTTP.REQ.HEADER("token").EXISTS)) The bit in bold makes sure that if "hash" is missing, I'm always getting a hit and the bit in cursive makes sure, that if "hash" is found, but either "authkey" or "token" is missing, I'm getting a hit
my postman requests to that responder rule seem to trigger the log action as expected
"simple and/or logic"
not the first nor the last time I run in to trouble with these
l
yeah it depends on when you want a hit I guess, since you specified in the beginning that you want to detect when it is present I was figuring you were building a NOOP action with this rule and a drop or whatever on true after that for example. you're just doing a negative policy while I thought you wanted a positive one from your first example 🙂
k
the idea is to eventually allow requests to pass only if "hash" is present and either "token" or "authkey" is present
l
so the screenshot I posted does exactly that if you NOOP that one and put a DROP all below 👀
k
Uhm, ok. Thanks
I got it working with one policy (above) so I'll go with that one