---
title: Next-Gen WAF for NGINX (Lua) 1.0.0+411
summary: null
url: >-
  https://www.fastly.com/documentation/reference/changes/2016/02/ngwaf-module-nginx-lua-1.0.0+411
---

- Originally HTTP methods that were inspected where explicitly listed (allowlisted, e.g. "GET",
  "POST"). The logic is now inverted to allow all methods not on an ignored list (blocklisted,
  e.g. "OPTIONS", "CONNECT"). This allows for the detection of invalid or malicious HTTP requests.
