A plug-and-play firewall library for Flask applications.
Project description
FlaskGuard 🚀
FlaskGuard is a plug-and-play firewall library for Flask applications. It protects your application from common web vulnerabilities such as SQL injection, XSS, path traversal, and more.
Features ✨
- 🔒 Detects and blocks malicious requests.
- ⚙️ Configurable rules and whitelist.
- 🛠️ Easy integration with Flask applications.
- 📜 Logging for blocked requests with color-coded output.
- 🧠 Advanced detection for SQL injection, XSS, path traversal, command injection, and more.
Installation 🛠️
From PyPI
Install FlaskGuard directly with Pip:
pip install safe-flask
From GitHub
Install FlaskGuard from the GitHub repository:
pip install git+https://github.com/CodeGuardianSOF/FlaskGuard.git
From Source
Clone the repository and install FlaskGuard locally:
git clone https://github.com/CodeGuardianSOF/FlaskGuard.git
cd FlaskGuard
pip install .
Usage 🚀
Basic Integration
from flask import Flask
from flask_guard import FlaskGuard
app = Flask(__name__)
FlaskGuard(app)
@app.route("/")
def home():
return "Welcome to FlaskGuard-protected app!"
if __name__ == "__main__":
app.run()
Custom Rules and Whitelist
from flask_guard.rules import load_user_config
custom_rules = {
"custom_rule": {
"enabled": True,
"pattern": r"custom_pattern",
"target": "query_string",
}
}
custom_whitelist = {
"query_string": [r"safe_custom_param=value"],
}
load_user_config(user_rules=custom_rules, user_whitelist=custom_whitelist)
Rules 🛡️
FlaskGuard includes the following built-in rules:
- SQL Injection: Detects SQL injection patterns such as
' OR 1=1,UNION SELECT,SLEEP(), and more. - XSS Attack: Detects Cross-Site Scripting (XSS) patterns in
<script>tags, event handlers, and encoded payloads. - Suspicious User-Agent: Blocks requests from tools commonly used in attacks, such as
sqlmap,curl,wget,python-requests, and more. - Path Traversal: Detects attempts to access sensitive files using patterns like
../../etc/passwd. - Remote and Local File Inclusion (RFI/LFI): Detects attempts to include remote or local files.
- Command Injection: Detects shell command injection patterns and common commands like
ls,cat,rm,bash, andpowershell. - Email Injection: Detects email header injection attempts using
BCC,CC, and newline characters. - HTTP Header Injection: Detects HTTP header injection attempts with patterns like
Set-CookieandContent-Length. - Directory Listing: Detects responses exposing directory listings, such as
Index of /. - Open Redirect: Detects potential open redirect vulnerabilities in query strings.
Testing the Firewall 🧪
You can test the firewall using curl commands. Below are examples of malicious requests:
SQL Injection
curl "http://127.0.0.1:5000/malicious?query=%27%20OR%201%3D1%20--"
XSS Attack
curl "http://127.0.0.1:5000/malicious?query=%3Cscript%3Ealert%281%29%3C%2Fscript%3E"
Path Traversal
curl "http://127.0.0.1:5000/malicious?query=../../etc/passwd"
Command Injection
curl "http://127.0.0.1:5000/malicious?query=ls%20-al"
Email Injection
curl "http://127.0.0.1:5000/malicious?query=TO:%20victim@example.com%0ABCC:%20attacker@example.com"
HTTP Header Injection
curl "http://127.0.0.1:5000/malicious?query=%0D%0ASet-Cookie:%20malicious=true"
Directory Listing
curl "http://127.0.0.1:5000/malicious?query=index%20of%20/"
Open Redirect
curl "http://127.0.0.1:5000/malicious?query=http://malicious-site.com"
Legitimate Request
curl "http://127.0.0.1:5000/safe?query=safe_param=value"
Contributing 🤝
See CONTRIBUTING.md for details.
License 📄
This project is licensed under the MIT License - see the LICENSE file for details.
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file safe_flask-2.0.0.tar.gz.
File metadata
- Download URL: safe_flask-2.0.0.tar.gz
- Upload date:
- Size: 7.5 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.1.0 CPython/3.13.2
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
89b52ec915d97fab781b40dbd61fabf93a0c798a6d96840f338639619d0f791b
|
|
| MD5 |
bccf120577c2fadc9f02f2379d1510d6
|
|
| BLAKE2b-256 |
4545cabf993c4c994c010cd1e4ee17b7efb8650d6c8c6c956545fab4e8ee14ce
|
File details
Details for the file safe_flask-2.0.0-py3-none-any.whl.
File metadata
- Download URL: safe_flask-2.0.0-py3-none-any.whl
- Upload date:
- Size: 8.4 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.1.0 CPython/3.13.2
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
5b2cdfefb869d4768bdd187671ecd8312c15010cd4d7c3426bfbffe32f41ad34
|
|
| MD5 |
01834adf6d61a843132461fca5cca206
|
|
| BLAKE2b-256 |
f12566698ea923611c7eb842c1d324c0d2f09c7c76b7085e9b901fe19f664bbe
|