DiscussionSLA

Wanted Improvements

Published 3 months ago

# SafeLine WAF
# šŸ–„ļø ui
# šŸ’Ŗ improve

Published 3 months ago

profile_photo

GamingForLiveYT

Updated 3 months ago

0

Hello SafeLine Team,
I've been using the WAF for quite a while and really like it. However, a few things have stood out to me, which I want to summarize in this post:

  1. Close Button Label: When editing a static file, the button used to close the file says "Disabled." I believe it should be changed to "Close" for clarity.

  2. Preview for Static Sites: I’d love to see a preview feature that renders the site instead of just showing an error for static sites. This could allow users to view various error pages, such as for 500-series errors.

  3. Dark Mode: I'm not sure if this is already in development, but a Dark Mode would be highly appreciated.

  4. Custom Error Pages per Domain: I feel like this has been requested already, but I’d still love to see it implemented. Possible ways this could be solved for me:

    • Allowing a static website to be loaded as a error page based on the Domains.
    • Having the ability to show the domain on the page itself, possibly by parsing it as a Java variable.
      (Note: the current solution is fine for me but expanding the Options here would definently bring improvements such as the Ability for custom Branding based on the Domain)
  5. Export Button for Logs: Add an export button to the log pages where users can specify a time range and potentially filter by target or source.
    (Note: i just discoverd that the "Logs" Section under "Attacks" already has an export button. I belive that this should also be Present on the "Events" Tab)

  6. Search Function for Applications Page: A search function would be helpful, especially as it becomes harder to find specific applications with over 40 entries. It should also allow filtering by comments.

  7. Improved Application Management:

    • Display comments when added.
    • Allow setting titles for applications to make them easier to differentiate, particularly when the same things are added for different URLs.
    • Improve readability of domain names on the page, as the grey text currently blends too much with the white background.
  8. Time Range for Dashboard: Add the ability to select a specific time range in the Simple Dashboard.

  9. Extended Log Retention: Provide an option to not clear out logs or to specify a retention period longer than 30 days.

  10. AbuseIPDB Integration:
    It would be highly beneficial, especially for users outside of SafeLine, to have an integration with AbuseIPDB. This would allow blocked IPs to be automatically reported to the database.

  11. Certificate Matching:
    I would Love it if the Error pages would attempt to find a Certificate thats Valid for the error url as to avoid the Unsecure Website error. I know that this is propabaly quiet resource intensive when done live but I belive that it would be possible to analyze a Certificate when its added and when aplicable just mark it somehow in the backend to be called upon when an error page is shown for a specific Url.
    I know that it is also possible to add a custom webpage that has *.domain configured and just add an error page there but that only handles 404 pages but comes with the benefit of customizability.
    On the Same note id also Love to be able to assign multiple certs to a single service and just have the WAF pick the fitting one as that avoids me from having to configure stuff for each domain separately that just stays the same only with a different url.

  12. Certificate Expiry Warning:
    i would love to see a popup or possible push notification for when a SSL cert is about to expire and has Expired or if a SSL Cert fails to renew. Those notifications could also be handeld by https://discord.com/channels/1243085666485534830/1326578984347111485/1326584478767906869

Thank you for considering these suggestions!
Jan

(edited to correct some mistakes that i made when initially writing this)
(editet again to add things ive realised / wanted to add)

profile_photo

GamingForLiveYT

Updated 3 months ago

0

Part2:

  1. SSL Certificate Listings:
    Please implement some sort of rollover / break in the Listed Applications from the SSL Certs so its not just one huge ever growing line
profile_photo

Monster

Updated 3 months ago

0

that's good

profile_photo

Marcino

Updated 3 months ago

0

host name variable šŸ™‚