AWS::WAFRegional::XssMatchSet> AWS WAF Classic support will end on September 30, 2025. > > This is *AWS WAF Classic* documentation. For more information, see [AWS WAF Classic](https://docs.aws.amazon.com/waf/latest/developerguide/classic-waf-chapter.html) in the developer guide. > > *For the latest version of AWS WAF* , use the AWS WAF V2 API and see the [AWS WAF Developer Guide](https://docs.aws.amazon.com/waf/latest/developerguide/waf-chapter.html) . With the latest version, AWS WAF has a single set of endpoints for regional and global use. A complex type that contains `XssMatchTuple` objects, which specify the parts of web requests that you want AWS WAF to inspect for cross-site scripting attacks and, if you want AWS WAF to inspect a header, the name of the header. If a `XssMatchSet` contains more than one `XssMatchTuple` object, a request needs to include cross-site scripting attacks in only one of the specified parts of the request to be considered a match.
import { CfnXssMatchSet } from 'aws-cdk-lib/aws-wafregional';Or use the module namespace:
import * as wafregional from 'aws-cdk-lib/aws-wafregional';
// wafregional.CfnXssMatchSetConfiguration passed to the constructor as CfnXssMatchSetProps.
nameRequiredstringThe name, if any, of the `XssMatchSet` .
xssMatchTuplesOptionalIResolvable | IResolvable | XssMatchTupleProperty[]Specifies the parts of web requests that you want to inspect for cross-site scripting attacks.
This L1 construct maps directly to the following CloudFormation resource type.
Our bi-weekly newsletter teaches hands-on AWS fundamentals. No certification fluff - just practical knowledge.
Subscribe to Newsletteraws-wafregionalAWS::WAFRegional::XssMatchSet