Skip to main content

A plug-and-play firewall library for Flask applications.

Project description

FlaskGuard 🚀

FlaskGuard is a plug-and-play firewall library for Flask applications. It protects your application from common web vulnerabilities such as SQL injection, XSS, path traversal, and more.

Features ✨

  • 🔒 Detects and blocks malicious requests.
  • ⚙️ Configurable rules and whitelist.
  • 🛠️ Easy integration with Flask applications.
  • 📜 Logging for blocked requests with color-coded output.
  • 🧠 Advanced detection for SQL injection, XSS, path traversal, command injection, and more.

Installation 🛠️

From PyPI

Install FlaskGuard directly from PyPI:

pip install safe-flask

From GitHub

Install FlaskGuard from the GitHub repository:

pip install git+https://github.com/username/FlaskGuard.git

From Source

Clone the repository and install FlaskGuard locally:

git clone https://github.com/username/FlaskGuard.git
cd FlaskGuard
pip install .

Usage 🚀

Basic Integration

from flask import Flask
from flask_guard import init_app

app = Flask(__name__)
init_app(app)

@app.route("/")
def home():
    return "Welcome to FlaskGuard-protected app!"

if __name__ == "__main__":
    app.run()

Custom Rules and Whitelist

from flask_guard.rules import load_user_config

custom_rules = {
    "custom_rule": {
        "enabled": True,
        "pattern": r"custom_pattern",
        "target": "query_string",
    }
}

custom_whitelist = {
    "query_string": [r"safe_custom_param=value"],
}

load_user_config(user_rules=custom_rules, user_whitelist=custom_whitelist)

Rules 🛡️

FlaskGuard includes the following built-in rules:

  1. SQL Injection: Detects SQL injection patterns such as ' OR 1=1, UNION SELECT, SLEEP(), and more.
  2. XSS Attack: Detects Cross-Site Scripting (XSS) patterns in <script> tags, event handlers, and encoded payloads.
  3. Suspicious User-Agent: Blocks requests from tools commonly used in attacks, such as sqlmap, curl, wget, and more.
  4. Path Traversal: Detects attempts to access sensitive files using patterns like ../../etc/passwd.
  5. Remote and Local File Inclusion (RFI/LFI): Detects attempts to include remote or local files.
  6. Command Injection: Detects shell command injection patterns and common commands like ls, cat, and rm.
  7. Email Injection: Detects email header injection attempts using BCC, CC, and newline characters.
  8. HTTP Header Injection: Detects HTTP header injection attempts with patterns like Set-Cookie and Content-Length.
  9. CSRF Token Missing (Optional): Detects requests missing CSRF tokens. This rule is disabled by default to avoid false positives. Enable it only if your app uses CSRF tokens.

Enabling the csrf_token_missing Rule

If your app uses CSRF tokens, you can enable the csrf_token_missing rule by updating the configuration:

from flask_guard.rules import load_user_config

custom_rules = {
    "csrf_token_missing": {
        "enabled": True,
    }
}

load_user_config(user_rules=custom_rules)

Testing the Firewall 🧪

You can test the firewall using curl commands. Below are examples of malicious requests:

SQL Injection

curl "http://127.0.0.1:5000/malicious?query=%27%20OR%201%3D1%20--"

XSS Attack

curl "http://127.0.0.1:5000/malicious?query=%3Cscript%3Ealert%281%29%3C%2Fscript%3E"

Path Traversal

curl "http://127.0.0.1:5000/malicious?query=../../etc/passwd"

Command Injection

curl "http://127.0.0.1:5000/malicious?query=ls%20-al"

Email Injection

curl "http://127.0.0.1:5000/malicious?query=TO:%20victim@example.com%0ABCC:%20attacker@example.com"

HTTP Header Injection

curl "http://127.0.0.1:5000/malicious?query=%0D%0ASet-Cookie:%20malicious=true"

Legitimate Request

curl "http://127.0.0.1:5000/safe?query=safe_param=value"

Contributing 🤝

See CONTRIBUTING.md for details.

License 📄

This project is licensed under the MIT License - see the LICENSE file for details.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

safe_flask-1.0.2.tar.gz (7.4 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

safe_flask-1.0.2-py3-none-any.whl (8.2 kB view details)

Uploaded Python 3

File details

Details for the file safe_flask-1.0.2.tar.gz.

File metadata

  • Download URL: safe_flask-1.0.2.tar.gz
  • Upload date:
  • Size: 7.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.13.2

File hashes

Hashes for safe_flask-1.0.2.tar.gz
Algorithm Hash digest
SHA256 c28da2c3f6ce10bd73504def69a7e4d3b730120c5f1bca58a1ac01dc64cce793
MD5 b44a1e38abc8eabc9031e8a752f5f894
BLAKE2b-256 4aed59ce0ebbd629a3ea3d6bcb04ffcf35fe4b1c059c9d5ab0f1523c544eb766

See more details on using hashes here.

File details

Details for the file safe_flask-1.0.2-py3-none-any.whl.

File metadata

  • Download URL: safe_flask-1.0.2-py3-none-any.whl
  • Upload date:
  • Size: 8.2 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.13.2

File hashes

Hashes for safe_flask-1.0.2-py3-none-any.whl
Algorithm Hash digest
SHA256 ffa7458c5e648907c42e029db32c00551c2c5d26c71eb0cca3bfd6e1f6c8a2b9
MD5 64a2e62cb646a84bfb9b2a7f07db7557
BLAKE2b-256 f5172b02c4091fef69a8027c95e2dc6208fb9cd030e8e09fe6d4717b108a10b3

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page