Open Source API Gateway
3. Security and Validation

clamav

Version

ClamAV is an open-source antivirus engine whose daemon, clamd, scans data sent to it over TCP. This plugin streams the headers and body of each message to clamd and blocks the message if a signature matches.

Compressed bodies are decompressed before scanning. Multipart bodies are scanned as a whole and part by part after decoding base64 and quoted-printable parts, including nested multiparts.

Harmful content is answered with a 500 Problem Details response of type security/potentially-harmful-content, and the message is not forwarded. Malformed multipart content, or content with an invalid Content-Type, is always rejected with a 500 error.

Example Configuration

api:
port: 2000
flow:
- clamav:
host: clamav.example.com
target:
url: https://api.predic8.de
api:
   port: 2000
   flow:
     - clamav:
         host: clamav.example.com
   target:
     url: https://api.predic8.de

Syntax

clamav:
host: <string>
onScanFailure: block
port: <string>
clamav:
  host: <string>
  onScanFailure: block
  port: <string>

Attributes

NameRequiredDefaultDescriptionExamples
hostfalselocalhostHostname or IP address of the clamd daemon.clamav.example.com
onScanFailurefalseblockWhat to do when a scan cannot complete, e.g. clamd is unreachable, times out or returns an error. block answers with a 500 error; pass forwards the unscanned message and logs a warning. Harmful and malformed content is blocked either way.pass
portfalse3310TCP port of the clamd daemon.-

Can be used in