I’m having issues on Apache Superset when trying to pass parameters using url_param, it detected as SQL Injection attempt from cloudflare.

This is the screenshot of the errors.

When i tried to explore more about the errors, i’m getting this from the cloudflare reports.

Is there any way to solve this ? on my first attempt to fix it, i tried to modify the query to standard query . it worked, but again, when i tried to use url_param, it blocked again .

A firewall rule to Bypass the WAF for the matching traffic would be needed in this case.

I would match the URL and the POST request method in the firewall rule, and then set the action to Bypass - WAF Managed Rules.

