Compressed bodies are decompressed before scanning. Multipart bodies are scanned as a whole and part by part after decoding base64 and quoted-printable parts, including nested multiparts.
Harmful content is answered with a 500 Problem Details response of type security/potentially-harmful-content, and the message is not forwarded. Malformed multipart content, or content with an invalid Content-Type, is always rejected with a 500 error.
Example Configuration
api:
port: 2000
flow:
- clamav:
host: clamav.example.com
target:
url: https://api.predic8.de
api:
port: 2000
flow:
- clamav:
host: clamav.example.com
target:
url: https://api.predic8.de
Syntax
clamav:
host: <string>
onScanFailure: block
port: <string>clamav: host: <string> onScanFailure: block port: <string>
Attributes
| Name | Required | Default | Description | Examples |
|---|---|---|---|---|
| host | false | localhost | Hostname or IP address of the clamd daemon. | clamav.example.com |
| onScanFailure | false | block | What to do when a scan cannot complete, e.g. clamd is unreachable, times out or returns an error. block answers with a 500 error; pass forwards the unscanned message and logs a warning. Harmful and malformed content is blocked either way. | pass |
| port | false | 3310 | TCP port of the clamd daemon. | - |