Our WAF was doing its job in production, but I couldn’t shake the feeling that something wasn’t right. That itch finally pushed me to dig into a long-standing idea: building a JVM-native WAF compatible with OWASP CRS. I wrote about the whole journey here:
blog.cloud-apim.com/building-a-j...