DEV Community

William Rodriguez
William Rodriguez

Posted on

Blocking SQLi and XSS in the pipeline: WafFilterStep.

Blocking SQLi and XSS in the pipeline: WafFilterStep.

Assuming external webhooks and user-submitted data are safe before saving them into your database is an invitation to data breaches. WafFilterStep guards your pipeline against SQLi and XSS automatically.

Here is how you use WafFilterStep & Input Sanitization in a production pipeline with wpipe-steps:

from wpipe import Pipeline
from wpipe_steps.security import WafFilterStep

pipeline = Pipeline(pipeline_name="secure_webhook_ingest")

pipeline.set_steps([
    # Inspect untrusted user inputs before any database insertion
    WafFilterStep.as_step(
        name="sanitize_input",
        keys_to_filter=["user_comment", "search_query"],
        strict_mode=True,  # Raises exception on detected threat
        response_key="waf_audit"
    )
])

# Malicious payload simulation
payload = {"user_comment": "Safe comment", "search_query": "1' OR '1'='1"}
result = pipeline.run(payload)
Enter fullscreen mode Exit fullscreen mode

Why developers love wpipe-steps:

  • 196 cataloged steps covering Redis, ClickHouse, MySQL, WAF, S3, Docker, and local HuggingFace AI.
  • Lazy-loading imports for instant sub-100ms startup times.
  • Clean .as_step() factory interface.

Check out the full repository on GitHub!

Top comments (0)