You can now use cf.appsec.request.failed_detections to control how your rules handle requests when a security detection reports a failure.
The field is an Array<String> of detection IDs that reports failures from content scanning, WAF attack score, attack signature detection, leaked credentials detection, and AI prompt detections for personally identifiable information (PII), prompt injection, custom topics, and unsafe topics.
The field does not alter the existing behavior of detections. Use it in rules to choose how to handle requests with reported failures.
When no failures are reported, the field returns []. You can use it on all plans, but your plan must still include the detections and rule features you want to use.
Supported rules:
- Custom rules at the zone and account levels
- Rate limiting rules at the zone and account levels
- Request Header Transform Rules at the zone level
Match any reported failure:
len(cf.appsec.request.failed_detections) gt 0
Match a reported leaked credentials detection failure:
any(cf.appsec.request.failed_detections[*] eq "waf_credential_check")
For more information, refer to the Failed detections field reference.
Source: Cloudflare


