Skip to main content
Drupal is a registered trademark of Dries Buytaert
Release: OpenID Connect / OAuth client 3.0.0-alpha9 New alpha version released for module openid_connect (3.0.0-alpha9). Release: Opensolr Search 4.5.0 Minor update available for module opensolr_search (4.5.0). Release: Timelinr 1.0.1 Minor update available for module timelinr (1.0.1). Usage Milestone: Simplify Module simplify crossed 10,000 active installs. Usage Milestone: Views Reference Filter Module entityreference_filter crossed 10,000 active installs. Usage Milestone: Dropdown Language Module dropdown_language crossed 10,000 active installs. Usage Milestone: Paragraphs Browser Module paragraphs_browser crossed 10,000 active installs. Usage Milestone: OpenAPI Module openapi crossed 10,000 active installs. Usage Milestone: Decoupled Router Module decoupled_router crossed 10,000 active installs. Module Revived: Entityqueue Buttons 1.1.2 Module entityqueue_buttons updated after 8 months of inactivity (1.1.2).

The Firewall module acts as a self-controlled web application firewall, allowing administrators to define rules for controlling inbound access based on hostnames, paths, HTTP methods, and parameter combinations. This enables granular control over different subdomains or public-facing paths within a Drupal site.

The Firewall module allows you to control inbound access based on rules with host, paths, methods, and parameter combination. It's a kind of self controlled "Web application firewall".

WARNING: This module is on early stage of development and there might be API changes etc. So the code can and should only be downloaded for testing by coders. When some review and bugfixing is done there will be a dev release.

Features

The first idea behind this module is restrict access to a full featured Drupal via different hosts for example in this way:

  • "admin.example.com" can be added to bypass list and should be secured by server controlled authentication or e.g. shield module if not available.
  • "editor.example.com" can also be protected by server. But there you can also add firewall rules to deny access to "/admin" paths and redirect zo admin.example.com.
  • "public.example.com" can get a firewall rule to allow all GET requests. But you can limit PUSH requests to single paths like /form/contact and allow only a list of parameters that are allowed to send.
    With the possibility to bypass via client IP you can allow access to special API paths and block them in "public.example.com".

Post-Installation

The configuration is only possible via settings.php to keep it very lightweight because of the Middleware situation. Keep sure that all host you would give access are not protected via core trusted_hosts setting.

Example config can be found on README.md

Depends on

Dependencies of the latest stable release

No dependencies recorded for this project.

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
1
Tracked since
Apr 2025
Latest release
1 year ago
Releases (12 mo)
0 ▼ from 1
Maintenance
Dormant

Releases

Version Type Core Release date
1.0.x-dev Dev 10–11 Apr 10, 2025