Admin endpoints for bans and clients on the single listener (closes #27)
check / check (push) Successful in 4m29s
check / check (push) Successful in 4m29s
SWWAF_ADMIN_TOKEN, or its _FILE form, opens GET and POST /_smallwebwaf/bans, DELETE /_smallwebwaf/bans/<client> and GET /_smallwebwaf/clients/<ip>. Unset, they answer 404; a missing or wrong token gets 401, in observe mode too. They go through every check, as the metrics do. POST takes a netblock or a client's address, a duration or permanent, and a reason, and makes an admin ban even while another lasts. DELETE lifts every active ban covering the address, kept and marked lifted. Bans come back as bans.json entries; a client as clients.json holds it, with its bans. Judgement call: answers leave out bans.json's version field. Judgement call: DELETE takes an address, not a netblock. Rule suppressed: gosec G304 on a test reading bans.json. Model: opus-5-5
This commit is contained in:
@@ -38,6 +38,14 @@ const HealthPath = "/_smallwebwaf/healthz"
|
||||
// SWWAF_METRICS_TOKEN.
|
||||
const MetricsPath = "/_smallwebwaf/metrics"
|
||||
|
||||
// BansPath is where an admin lists and adds bans, and, followed by / and
|
||||
// a client's address, lifts them, with SWWAF_ADMIN_TOKEN.
|
||||
const BansPath = "/_smallwebwaf/bans"
|
||||
|
||||
// ClientsPath is where an admin asks what smallwebwaf knows of a client,
|
||||
// by the client's address after it, with SWWAF_ADMIN_TOKEN.
|
||||
const ClientsPath = "/_smallwebwaf/clients/"
|
||||
|
||||
// Params are what New needs.
|
||||
type Params struct {
|
||||
Config *config.Config
|
||||
|
||||
Reference in New Issue
Block a user