Skip to content
Myra Online Help Updated · 25 Aug 2026

Listing all applicable WAF rules of a subdomain

Note

The response collects the WAF rules of all levels in one list. It replaces the separate requests for subdomain, domain and tag rules.

Sends a GET request to the endpoint /domain/{id}/waf-rules/list.

Description

The List-Combined-WAF-Rules request allows the user to request a list of all WAF rules that apply to a subdomain of a domain of the organisation.

The list contains the WAF rules of the subdomain, the general WAF rules of the domain and the WAF rules of the tags that are assigned to the subdomain or to the domain. The system sorts the rules by their level and, within a level, by the value of the attribute sort.

Requirements

Values of the request: Domain-ID {id}

Objects: none

Request

To request a list of all applicable WAF rules, the Domain-ID {id} needs to be added to the path of the request.

The List-Combined-WAF-Rules request allows you to filter the output by adding the following parameters to the path of the request:

Parameters Description Values
subDomain Also returns the WAF rules of this subdomain and of the tags that are assigned to it. Without this parameter, the list contains the rules on domain level only. a string
page Specifies the page of the result list. integer
pageSize Specifies the number of entries per page. The value -1 returns all entries in one response. integer

As a result, the user gets one or more objects CombinedWafRuleVO with the requested information.

The object CombinedWafRuleVO contains all attributes of the object WafRuleVO and, in addition, the following attribute:

Attributes Description Values
ruleLevel The level the WAF rule is defined on.
  • 1 -> rule of the subdomain
  • 2 -> rule of the domain
  • 3 -> rule of a tag of the subdomain
  • 4 -> rule of a tag of the domain
  • 5 -> rule of a Myra tag of the subdomain
  • 6 -> rule of a Myra tag of the domain

For the information the object WafRuleVO provides and for the attributes of the objects WafActionVO and WafConditionVO, refer to the section Listing all WAF rules of all subdomains.

Example

Example response:

[
  {
    "objectType": "string",
    "id": 0,
    "modified": "string",
    "created": "string",
    "comment": "string",
    "ruleType": "string",
    "ruleLevel": 0,
    "name": "string",
    "description": "string",
    "logIdentifier": "string",
    "template": true,
    "subDomainName": "string",
    "vhostId": 0,
    "tagId": 0,
    "direction": "string",
    "uuid": "string",
    "processNext": true,
    "sync": true,
    "actions": [
      {
        "objectType": "string",
        "id": 0,
        "name": "string",
        "type": "string",
        "availablePhases": 0,
        "customKey": "string",
        "value": "string"
      }
    ],
    "conditions": [
      {
        "objectType": "string",
        "id": 0,
        "name": "string",
        "key": "string",
        "value": "string",
        "matchingType": "string",
        "availablePhases": 0,
        "alias": "string"
      }
    ],
    "sort": 0,
    "copiedFrom": 0,
    "expireDate": "string",
    "enabled": true
  }
]

Responses

The following responses are available:

STATUS CODE DESCRIPTION
200 The request has succeeded.
400 The request was unsuccessful. The request was invalid or information is missing.
401 The request has not succeeded because the user authentication was incorrect.
403 The request has not succeeded because the user does not have the right permissions.