//! WAF awareness — telling the edge apart from the application. //! //! When a WAF sits in front of a target, every response an agent reads may //! have been written by the edge rather than by the application. That breaks //! inference in two opposite directions at once, and both are common: //! //! ```text //! payload → 403 from Cloudflare → "not vulnerable" ← false NEGATIVE //! payload → block page echoing it → "payload reflected!" ← false POSITIVE //! ``` //! //! The first is the expensive one. A WAF blocking a probe says nothing about //! the code behind it: the application may be wide open and simply never //! reached. Reporting "SQL injection tested, not vulnerable" on the strength of //! a 403 from the edge is a statement about the WAF, not the app — and it is //! the statement that gets a real bug missed. //! //! The second is the embarrassing one. A block page frequently includes the //! offending payload ("Your request contained: `