The WAF is in good condition, this is my starting point: shadow mode with reporting, replay of captured traffic bot detection (fingerprint header) intel threats (AbuseIPDB, AlienVault) GraphQL: depth, complexity, batch, introspection OpenAPI: request validation against specs WASM plugin in sandbox (off by default) multi-tenant PostgreSQL with per-row isolation auth: local, OAuth2+PKCE, LDAP, SAML (XML-DSig), MFA/TOTP RBAC for endpoints on the Admin API Svelte dashboard, audit log, privacy editing

Show HN: I Wrote a WAF in Rust with Pingora
github.com