# Discourse + Web Application Firewall (WAF) mod\_security

**URL:** https://meta.discourse.org/t/discourse-web-application-firewall-waf-mod-security/133612
**Category:** Self-hosting
**Tags:** unsupported-install, hosting
**Created:** [November 17, 2019, 1:37pm UTC](https://meta.discourse.org/t/discourse-web-application-firewall-waf-mod-security/133612 "2019-11-17T13:37:55Z")
**Posts on this page:** 1
**Showing post:** 6

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [November 18, 2019, 6:50am UTC](https://meta.discourse.org/t/discourse-web-application-firewall-waf-mod-security/133612/6 "2019-11-18T06:50:14Z")

</div>

I think the desire for some magic device that auto mitigates issues is somewhat misguided in the Discourse setup. We have a bounty program, we patch issues in Discourse within hours of when they are reported. Sites run `tests-passed` by default which in today’s case contains commits from today.

Sure if you are running software that was exploited years ago and you have no freedom to upgrade cause … reasons… a WAF makes sense cause it could save you. But in the case of Discourse I think it is at best misguided.

---

_[View the full topic](https://meta.discourse.org/t/discourse-web-application-firewall-waf-mod-security/133612)._
