Keep the bans, the clients and GeoJS's answers in state files (closes #17)
check / check (push) Successful in 3m53s
check / check (push) Successful in 3m53s
smallwebwaf now copies its state to bans.json, clients.json and lookups.json in SWWAF_STATE_DIR, as "Persistent state" in SPEC.md describes, and reads them back at start, so a restart lifts no ban and gives no client a fresh allowance. Each client gains a history, and a ban's notes count the netblock's requests. bans.json is written SWWAF_STATE_WRITE_DELAY after a ban, every file every SWWAF_STATE_COUNTER_INTERVAL and at the stop, each through a synced temporary file renamed over it. A file that does not parse, an unknown version or an unwritable directory stops the start. The image gets /var/lib/smallwebwaf, which the run script gives to the smallwebwaf user. Deviation: no AS number or name, and no ban cause, reason or lifting yet. Model: opus-5-5
This commit is contained in:
@@ -36,7 +36,8 @@ func (rq *request) limitBroken(now time.Time) bool {
|
||||
return false
|
||||
}
|
||||
|
||||
ban := rq.h.ledger.BanForLimit(rq.netblock(), now, bans.Notes{
|
||||
netblock := rq.netblock()
|
||||
ban := rq.h.ledger.BanForLimit(netblock, now, bans.Notes{
|
||||
Country: rq.line.Country,
|
||||
Limit: hit.Limit,
|
||||
Window: hit.Window,
|
||||
@@ -49,6 +50,8 @@ func (rq *request) limitBroken(now time.Time) bool {
|
||||
Status: rq.h.config.BanResponse,
|
||||
UserAgent: rq.in.UserAgent(),
|
||||
},
|
||||
// The histories count this request only once it has ended.
|
||||
Requests: rq.h.limiter.Requests(netblock) + 1,
|
||||
})
|
||||
rq.h.limiter.Reset(group)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user