For AI agents: a documentation index is available at the root level at /llms.txt. Append /llms.txt to any URL for a page-level index, or .md for the markdown version of any page.
LogoLogo
HUMAN DashboardHUMAN WebsiteRequest a Demo
Product GuidesEnforcer GuidesMobile SDKAPI ReferenceCustomer support
Login
Product GuidesEnforcer GuidesMobile SDKAPI ReferenceCustomer support
  • General
    • About Enforcers
    • Support first-party HUMAN calls
    • Deploy Tool
    • Troubleshoot Enforcer configurations
  • Enforcer frameworks
    • Akamai ESI
    • Apache - C Module
    • ASP.NET
    • Callout Enforcer
    • Envoy Proxy
    • F5 BIGIP
    • Fastly JavaScript Compute@Edge
    • Google Cloud Platform (GCP) Callout Enforcer
    • Kong Plugin
    • NGINX - C Module
    • NGINX - LUA Module
      • Changelog
      • Supported Features
      • Installing the Enforcer
      • Configuration Options
      • Upgrading the Enforcer
      • HUMAN Plugin Configuration
      • First Party Configuration
      • Enrichment
    • PHP
    • Python
    • Ruby
    • Salesforce Commerce Cloud Cartridge
  • About Enforcers
  • Support first-party HUMAN calls
  • Deploy Tool
  • Troubleshoot Enforcer configurations
  • Akamai EdgeWorker changelog
  • Installation
  • Manual installation
  • Configuration
  • API
  • Upgrading
  • Supported Features
  • Install the Akamai EdgeWorker Enforcer
  • Configuration Options
  • Upgrading the Enforcer
  • Akamai ESI
  • Akamai ESI changelog
  • Installation
  • Configuration
  • First Party Configuration
  • Apache - C Module
  • Apache changelog
  • Module Configuration
  • Configuration Options
  • First Party Configuration
  • Apigee Edge changelog
  • Installation
  • Configuration
  • ASP.NET
  • ASP.NET changelog
  • Configuration
  • Changelog
  • Installation
  • API
  • Configuration
  • Changelog
  • Installation
  • Configuration
  • AWS Lambda@Edge changelog
  • Installation
  • Manual installation
  • API
  • Configuration
  • Upgrading
  • Supported Features
  • Installing the Enforcer
  • Configuration Options
  • Upgrading the Enforcer
  • Changelog
  • Install the Azure Front Door Enforcer
  • Manually install the Azure Front Door Enforcer
  • API
  • Configuration
  • Callout Enforcer
  • Changelog
  • Supported Features
  • Envoy configuration
  • Enforcer Configuration
  • Advanced Configuration
  • Docker Image
  • Complete Example
  • Cloudflare Worker changelog
  • Installation
  • Installation with Terraform
  • Manual installation
  • Deploy the Cloudflare Enforcer for Shopify applications
  • API
  • Configuration
  • Configuration (v5 and Below)
  • Upgrading to Version 6
  • Changelog
  • Installation
  • API
  • Configuration
  • Changelog
  • Installation
  • API
  • Configuration
  • Envoy Proxy
  • Changelog
  • Installation
  • Configuration Options
  • First Party Configuration
  • F5 BIGIP
  • Changelog
  • Installation
  • First Party Integration
  • Configuration
  • Configurational Classes
  • Advanced Customization
  • Troubleshooting
  • Fastly JavaScript Compute@Edge
  • Changelog
  • Installation
  • API
  • Configuration
  • Fastly Rust Compute@Edge changelog
  • Supported Features
  • Installation
  • Configuration
  • Changelog
  • Installation
  • Manual installation
  • Configuration
  • How it works
  • Upgrade to V12
  • Installation
  • Configuration
  • How It Works
  • Upgrade to V11
  • Installation
  • Configuration
  • How It Works
  • Upgrade to V10
  • Installing the Enforcer
  • GraphQL Support
  • Sensitive GraphQL Operations
  • Basic Configuration
  • Customized Subroutines
  • Additional Activity Handler
  • Advanced Blocking Response
  • Creating and Configuring the Edge-Dictionary
  • Custom CSS
  • Custom First Party Sensor Endpoint
  • Custom Logo
  • Custom JS Script
  • Custom Parameters
  • Filter Requests
  • Filter by HTTP Method
  • Filter by Route
  • Filter by Extension
  • Filter by IP
  • Filter by User Agent
  • Data Enrichment
  • First Party
  • First Party Snippet
  • Enforced Routes
  • Login Credentials Extraction
  • Modify First Party Response
  • Module Context Object
  • Module Enabled
  • Module Mode
  • Monitored Routes
  • Returning A Custom Block Page
  • Sensitive Routes
  • Test Block Flow on Monitoring Mode - Bypass Monitor Header
  • Upgrading the Enforcer
  • Changelog
  • Installation
  • API
  • Configuration
  • Installing the Enforcer
  • Supported Features
  • Configuration Options
  • Upgrading the Enforcer
  • Google Cloud Platform (GCP) Callout Enforcer
  • Integrate the GCP Callout Enforcer
  • HAProxy changelog
  • Supported Software Versions
  • Supported Features
  • Installation
  • Configuration
  • Java changelog
  • Installation
  • Configuration
  • Upgrading
  • Kong Plugin
  • Changelog
  • NGINX Gateway Fabric with the HUMAN Enforcer
  • NGINX Gateway Fabric Enforcer configurations
  • Ingress NGINX controller
  • Ingress NGINX Enforcer configuration options
  • Changelog
  • Installation
  • Configuration options
  • Changelog
  • Installation
  • Configuration options
  • Changelog
  • Installation (Next.js 16)
  • Installation (Next.js 15 and lower)
  • Configuration
  • NGINX - C Module
  • NGINX changelog
  • Supported Features
  • Installation
  • Module Configuration
  • Configuration Options
  • Enrichment
  • First Party Configuration
  • Nginx Docker Image
  • Ingress NGINX Controller with HUMAN Enforcer
  • NGINX - LUA Module
  • Changelog
  • Supported Features
  • Installing the Enforcer
  • Configuration Options
  • Upgrading the Enforcer
  • HUMAN Plugin Configuration
  • First Party Configuration
  • Enrichment
  • Changelog
  • Installation
  • API
  • Configuration
  • Configuration Options (7.9.0 and below)
  • Upgrading to Version 8
  • PHP
  • Changelog
  • Upgrading
  • Configuration Options
  • Advanced Configuration
  • Python
  • Changelog
  • Installation
  • Required Configuration
  • Configuration Options
  • Upgrading
  • First Party Configuration
  • Ruby
  • Changelog
  • Installation
  • Configuration
  • Additional Information
  • Salesforce Commerce Cloud Cartridge
  • Changelog
  • Importing the Cartridge
  • Registering the Cartridge
  • Importing Metadata and Services
  • Configuring the Cartridge
  • Using the Cartridge
  • SCAPI Protection Considerations
  • Upgrading
  • Customized Block Page
  • Configuration options
  • First Party
  • Varnish changelog
  • Supported Software Versions
  • Installation
  • Configuration Options
  • Enforcer Configuration
  • Example configuration
HUMAN DashboardHUMAN WebsiteRequest a Demo
On this page
  • September 30, 2025
  • Version 7.3.6
  • June 30, 2025
  • Version 7.3.5
  • December 26, 2024
  • Version 7.3.4
  • July 19, 2024
  • Version 7.3.3
  • July 17, 2024
  • Version 7.3.2
  • Version 7.3.1
  • June 13, 2023
  • Version 7.3.0
  • April 20, 2023
  • Version 7.2.1
  • April 13, 2023
  • Version 7.2.0
  • June 27, 2022
  • Version 7.1.3
  • June 22, 2022
  • Version 7.1.2
Enforcer frameworksNGINX - LUA Module

Changelog

September 30, 2025
September 30, 2025

June 30, 2025
June 30, 2025

December 26, 2024
December 26, 2024

July 19, 2024
July 19, 2024

July 17, 2024
July 17, 2024

June 13, 2023
June 13, 2023

April 20, 2023
April 20, 2023

April 13, 2023
April 13, 2023

June 27, 2022
June 27, 2022

June 22, 2022
June 22, 2022
Older posts
Next
Built with
Login

Version 7.3.6

Added

  • Support for additional_risk_info feature
  • is_sensitive_route field to Risk API and async activities

Version 7.3.5

Added

  • Whitelist by request host name

Version 7.3.4

Changed

  • Automatically inspect GraphQL POST data

Fixed

  • GraphQL default path

Version 7.3.3

Fixed

  • Rate limit code for JSON responses

Version 7.3.2

Fixed

  • Rate limit code

Version 7.3.1

Changed

  • Remove lua-resty-nettle version restriction

Fixed

  • Install PX package symlink in OpenResty Lua directory

Version 7.3.0

Added

  • CORS support
  • Set X-PX-COOKIES as the default custom cookie name
  • _M.px_login_creds_settings configuration, to allow specify CI settings in Lua configuration file

Changed

  • Rename px_graphql_paths to px_graphql_routes

Fixed

  • Correctly add GraphQL routes (requests must contain specified GraphQL Type/Name) to sensitive routes

Version 7.2.1

Added

  • custom_sensitive_routes a custom function to determine if URL path is a sensitive route

Version 7.2.0

Added

  • custom_enabled_routes a custom function to determine if url path is an enabled route
  • px_graphql_paths to specify a list of GraphQL endpoints
  • Support for JWT and pxcts

Changed

  • Support for multiple GraphQL endpoints

Fixed

  • Add CI paths to the sensitive routes

Version 7.1.3

Fixed

  • Export ngx.ctx.pxde variable

Version 7.1.2

Fixed

  • Properly handle multiple instances of the same header
  • Field name in telemetry command