Execution Order

The order in which OpenResty Edge runs Global Rewrite Rules, page rules, and page rule actions for an HTTP or HTTPS request, and which one takes effect when several of them set the same thing.

This page explains the execution order of Global Rewrite Rules, page rules, and page rule actions for HTTP and HTTPS requests. It also explains which setting takes precedence when several rules or settings affect the same item.

Use it to understand how features interact. For example, it shows whether WAF inspects a URI rewritten by a page rule and whether a response header action applies to a cached response.

This page applies to OpenResty Edge 26.9.1-1 and later 26.9 releases. It covers HTTP and HTTPS applications only.

Version Labels

The Version column shows the first OpenResty Edge release that includes an item:

  • An empty cell means the item was available before OpenResty Edge 22.12.1-1.
  • A version such as 24.9.1-1 is the first release that includes the item.
  • Coming soon means the item is not in a released version yet.

Overview

The stages of an HTTP request in OpenResty Edge

After the node identifies the application, it handles the request in these stages:

  1. Global Rewrite Rules: Run for every application in the partition.
  2. Application rules: The custom Edge language rules and the page rules of the application run.
  3. Pre-proxy processing: Apply the final URI, enable error pages, decide caching and the upstream, then run WAF.
  4. Cache and upstream: Look up the cache. On a miss, send the request to the upstream.
  5. Response headers: Run response header actions.
  6. Response body: Run response body actions and compression.
  7. Logging: Write logs and send events.

Some actions can end a request before the cache and upstream stage, including Exit the current request and return status code, a rejected rate limit, and a WAF block. The node skips the remaining request processing and generates a response. That response still passes through the response headers, response body, and logging stages. See Requests Rejected Before WAF and Responses Sent Before WAF for the differences.

Rule Order

When a rule matches, its parts run in this order:

  1. Run the Action list from top to bottom. A Global Custom Action runs according to its position in the list.
  2. WAF: Register a WAF check. The node runs the check during pre-proxy processing.
  3. Content: Send the configured content and stop processing later page rules. See Responses Sent Before WAF.
  4. Proxy: Record the upstream configuration. The node resolves the upstream during pre-proxy processing.
  5. Cache: Record the cache settings. The node applies them during pre-proxy processing.
  6. Skip any subsequent page rules when this rule matches: Stop processing later page rules.

When Actions Take Effect

  • At the rule: The action runs as soon as its rule matches. Later rules see the result.
  • Pre-proxy processing or Response headers: The action records a setting, which the node applies during the named stage.

The Ends the request column shows whether an action ends the request in its rule. Always means that it always ends the request. A condition means that it does so only when the condition is met. An empty cell means that the action does not end the request.

ActionTakes effectEnds the requestVersion
Set URIAt the rule
Add URI prefixAt the rule
Remove URI prefixAt the rule
Remove URI segmentAt the rule
Set URI argumentAt the rule
Add URI argumentAt the rule
Remove URI argumentAt the rule
Set request headerAt the rule
Add request headerAt the rule
Remove request headerAt the rule
Set variableAt the rule
Log error messageAt the rule
DelayAt the rule
Using EdgelangAt the rule
Run Lua moduleAt the rule
Mirror RequestAt the rule
Record WAF logsAt the rule23.3.1-1
Set uploaded file argumentsAt the rule23.3.1-1
Enable S3 authenticationAt the rule25.9.1-1
Limit request rateAt the ruleWhen it rejects the request
Limit request countAt the ruleWhen it rejects the request
Limit request concurrencyAt the ruleWhen it rejects the request24.9.2-1
Block RequestAt the ruleWhen it rejects the request
Block IP ListAt the ruleWhen the client IP is in the list26.3.2-1
Enable Basic AuthenticationAt the ruleWhen authentication fails
Enable OpenIDC AuthenticationAt the ruleWhen it redirects the client to the identity provider
OAuth2 JWT validateAt the ruleWhen validation fails
OAuth2 introspection validateAt the ruleWhen validation fails
Enable hCaptchaAt the ruleWhen the client has not passed the challenge
Enable OpenResty Edge Built-in CaptchaAt the ruleWhen the client has not passed the challenge
Enable Private Access TokenAt the ruleWhen the client has not passed the challenge26.9.1-1
Enable Circuit BreakerAt the ruleWhen the circuit is open
Enable CSRF tokenAt the ruleWhen the token check fails23.3.1-1
Enable SSL client verifyAt the ruleWhen the client certificate check fails
Block IPAt the ruleAlways26.3.2-1
Exit the current request and return status codeAt the ruleAlways
RedirectAt the ruleAlways
Close ConnectionAt the ruleAlways24.9.1-1
Output response bodyAt the ruleAlways
Return static fileAt the ruleAlways
Set maximum request body sizePre-proxy processing
Set proxy URIPre-proxy processing
Rewrite proxy URI prefixPre-proxy processing
Set proxy hostPre-proxy processing
Custom error pagePre-proxy processing
Set proxy headerCache and upstream
Append proxy header valueCache and upstream
Pass request headersCache and upstream25.12.1-1
Pass request bodyCache and upstream25.12.1-1
Use Downstream Server Address as Upstream Source AddressCache and upstream22.12.1-1
Enable WebSocketCache and upstream
Enable proxy cache revalidateCache and upstream
Use stale proxy cacheCache and upstream
Proxy cache bypassCache and upstream26.6.14-1
Proxy no cacheCache and upstream26.6.14-1
Disable request bufferingCache and upstream
Disable proxy response bufferingCache and upstream23.12.1-1
Intercept Upstream ErrorsCache and upstream
Follow HTTP redirectCache and upstream26.9.2-1
Enable HTTP sliceCache and upstreamComing soon
Set response headerResponse headers
Add response headerResponse headers
Remove response headerResponse headers
Set response cookieResponse headers
Set response cookie SameSiteResponse headers23.3.1-1
Set expiration timeResponse headers
Apply standard MIME typesResponse headers
Response body filterResponse body23.3.1-1
Capture response bodyResponse body
Enable gateway GzipResponse body
Enable gateway BrotliResponse body
Enable gateway ZstandardResponse body25.6.1-1
Set Gzip TypesResponse body
Set Brotli TypesResponse body
Set Zstandard TypesResponse body25.6.1-1
Limit response data rateResponse body
Enable OpenTelemetry TraceLogging24.9.2-1
Set OpenTelemetry Span NameLogging24.9.2-1
Enable limit traffic eventLogging
Enable circuit breaker eventLogging
Disable Access LogLogging

Set URI and the other URI actions immediately change the URI seen by later rules. The node applies the final URI during pre-proxy processing.

Enable CSRF token checks the token at the rule and injects tokens during the response body stage.

Mirror Request sends a copy of the request at the rule and waits for it to finish. With Asynchronous Request Mirroring, the node sends the copy during the cache and upstream stage without waiting. It does not send a copy if the request ends earlier.

The OpenTelemetry actions mark the request for tracing. The node exports the span when the request ends.

These reject options of the rate limit actions and Block Request were added after 22.12.1-1:

  • JavaScript Challenge and Redirect Validate (23.3.1-1)
  • Return Page Template (24.3.1-1)
  • Mark as Rejected (24.9.7-1)
  • Block IP (26.3.2-1)
  • Private Access Token (26.9.1-1)
  • No Delay was added in 24.9.1-1.
  • Log Delay was added in 26.9.20-1.
  • Coming soon: Log Only only records the request in the DoS log in the logging stage and never delays or rejects it.

Requests Rejected Before WAF

The request ends at the rule and skips the pre-proxy processing stage in these cases:

  • A rate limit action or Block Request rejects the request.
  • Block IP runs, or Block IP List matches the client. The node closes the connection and writes no access log.
  • Enable Basic Authentication, OAuth2 JWT validate, or OAuth2 introspection validate fails.
  • Enable hCaptcha, Enable OpenResty Edge Built-in Captcha, or Enable Private Access Token challenges a client that has not passed the challenge.
  • Enable OpenIDC Authentication redirects the client to the identity provider.
  • An Enable Circuit Breaker action finds the circuit open.

Responses Sent Before WAF

Output response body, Return static file, and the Content section send the response before WAF runs.

Priority for Conflicts and Shared Items

Between Rules

In this table, “first” and “last” refer to execution order. Global Rewrite Rules run first. Page rules then run in this order: Always-Top rules, normal rules, and Always-Bottom rules. Each group runs from top to bottom.

Within a rule, the Action list runs first, followed by the WAF, Content, Proxy, and Cache sections. A later setting overrides an earlier one.

ItemWhich one takes effect
Proxy to upstream in the Proxy sectionThe matching rule that runs last
Cache key components and the other options of the Cache sectionThe matching rule that runs last. For Caching by Default, see the next two rows.
Caching by Default for status 200The matching rule that runs last
Caching by Default for other status codesIn released versions, the first matching rule. Coming soon: the matching rule that runs last, the same as for status 200.
Set proxy URI and Rewrite proxy URI prefixThe action that runs last
Set proxy hostThe action that runs last
Set maximum request body sizeThe action that runs last
Custom error page for the same status codeThe action that runs last
Set expiration time and Browser CacheThe one that runs last. In the same rule, Browser Cache runs after the Action list and wins.
Set request header, Set proxy header, or Set URI argument for the same nameThe action that runs last. Add request header and Add URI argument add another value instead.
Set request header and Set proxy header for the same headerThe upstream receives the Set proxy header value. Later rule conditions and WAF see the Set request header value.
Set response header, Add response header, and Remove response header for the same nameApplied in the order they ran. Set response header also replaces a header of the same name from the upstream.
Set expiration time or Browser Cache, and a response header action for Cache-Control or ExpiresSet expiration time or Browser Cache, which the node applies after the response header actions
WAF sections of several rulesEvery registered check runs, in rule order. The first check that blocks the request ends it.
Rate limit actions and Block Request in several rulesEvery matching action runs at its rule and counts on its own. The first one that rejects the request ends it.

Between Page Rules and Settings

Some items can also be set in the application Settings and in Global Config > General. For a request that a page rule matches, the page rule action takes effect. An application setting takes effect over the global setting unless it is set to Using the Global configuration.

ItemPriority, from highest to lowest
Request body size limitSet maximum request body size action, Apply custom max request body size in the application Settings, Maximum request body size in Global Config
GzipEnable gateway Gzip and Set Gzip Types actions, Gzip compression of responses in the application Settings, Gzip in Global Config
BrotliEnable gateway Brotli and Set Brotli Types actions, Brotli compression of responses in the application Settings, Brotli in Global Config
ZstandardEnable gateway Zstandard and Set Zstandard Types actions, Zstandard compression of responses in the application Settings, Zstandard in Global Config
Cache revalidationEnable proxy cache revalidate action, Proxy cache revalidate in the application Settings, Proxy cache revalidate in Global Config
Stale cacheUse stale proxy cache action, Apply custom stale proxy cache in the application Settings, Use stale proxy cache in Global Config
Upstream error interceptionIntercept Upstream Errors action, Intercept the origin site’s error pages in Global Config. Follow HTTP redirect also turns interception on.
Error page for a status codeCustom error page action, Enable OpenResty Edge error pages in Global Config

The application settings are applied after the Global Rewrite Rules. An application setting that is not set to Using the Global configuration therefore overrides the same action in a Global Rewrite Rule. The request body size limit from the application Settings or Global Config also overrides a Set maximum request body size action in a Global Rewrite Rule.

WAF

When a page rule matches, its WAF section registers a WAF check. The node runs all registered checks during pre-proxy processing, after all page rules and the custom Edge language rules at the end of the page. For configuration instructions, see Enable WAF for an Application.

As a result:

  • WAF inspects the request as the page rules left it, including a rewritten URI, changed request headers, and the request body.
  • Actions in both earlier and later rules run before WAF. A rate limit, captcha, or authentication check can end the request before WAF runs. Actions such as Exit the current request and return status code allow WAF to run before the request ends.
  • Output response body, Return static file, and the Content section send the response before WAF runs.
  • WAF Whitelist conditions are checked before the page rules run, against the original request. The matching entries apply to every WAF check.
  • WAF runs before the cache lookup, so it also inspects requests that the cache answers.
  • WAF currently inspects requests only and does not support inspecting responses yet. With the Log only block action, Capture Response Body (23.6.1-1) adds part of the response body to the WAF log.
  • A blocked request still passes through the response headers, response body, and logging stages, so response header actions and logging apply to the block response.

These WAF options were added after 22.12.1-1: the Close connection, Redirect Validate, and JavaScript Challenge block actions (23.3.1-1), Paranoia Level (26.6.1-1), and the Private Access Token and Custom Action block actions (26.9.1-1).