Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
ac7a26123f |
@@ -118,6 +118,23 @@ func TestOnlyTheChosenEventsAreSent(t *testing.T) {
|
||||
})
|
||||
}
|
||||
|
||||
func TestWouldSendOnlyForTheChosenEvents(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
params := newParams()
|
||||
params.Events = []string{alerts.EventSourceFailure, alerts.EventFileError}
|
||||
q := alerts.New(params)
|
||||
|
||||
if q.WouldSend(alerts.EventBan, netblock(1)) ||
|
||||
q.WouldSend(alerts.EventPermanentBan, netblock(1)) {
|
||||
t.Error("a ban alert would be sent, though SWWAF_ALERT_EVENTS leaves it out")
|
||||
}
|
||||
|
||||
if !q.WouldSend(alerts.EventFileError, netip.Prefix{}) {
|
||||
t.Error("a file_error alert would not be sent")
|
||||
}
|
||||
}
|
||||
|
||||
func TestNothingIsQueuedWithoutAWebhook(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
@@ -132,6 +149,18 @@ func TestNothingIsQueuedWithoutAWebhook(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestWouldSendNothingWithoutAWebhook(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
params := newParams()
|
||||
params.WebhookURL = nil
|
||||
q := alerts.New(params)
|
||||
|
||||
if q.WouldSend(alerts.EventBan, netblock(1)) {
|
||||
t.Error("an alert would be sent with no webhook set")
|
||||
}
|
||||
}
|
||||
|
||||
func TestRepeatWithinTheCooldownIsHeldBackAndCountedInTheNext(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
|
||||
@@ -376,6 +376,40 @@ func TestWouldBanGivesTheBanWithoutMakingIt(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestWouldBePermanentAnswersAsTheBanWouldBeMade(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
ledger := bans.New(defaultRules())
|
||||
netblock := netip.MustParsePrefix("203.0.113.9/32")
|
||||
now := midnight()
|
||||
|
||||
// Five bans for a limit in a row, of 1, 3, 9, 27 and 81 hours, are not
|
||||
// permanent. The sixth, of 243 hours, would be, while a first ban for
|
||||
// an attack would not.
|
||||
for i := range 5 {
|
||||
if ledger.WouldBePermanent(netblock, now, bans.CauseLimit) {
|
||||
t.Fatalf("ban %d for a limit would be permanent", i+1)
|
||||
}
|
||||
|
||||
ban, _ := ledger.BanForLimit(netblock, now, bans.Notes{})
|
||||
now = ban.Expires
|
||||
}
|
||||
|
||||
if !ledger.WouldBePermanent(netblock, now, bans.CauseLimit) {
|
||||
t.Error("the sixth ban for a limit would not be permanent")
|
||||
}
|
||||
|
||||
if ledger.WouldBePermanent(netblock, now, bans.CauseAttack) {
|
||||
t.Error("a first ban for an attack would be permanent")
|
||||
}
|
||||
|
||||
// Once a first ban for an attack has ended, the next would be permanent.
|
||||
attack, _ := ledger.BanForAttack(netblock, now, bans.Notes{})
|
||||
if !ledger.WouldBePermanent(netblock, attack.Expires, bans.CauseAttack) {
|
||||
t.Error("a second ban for an attack would not be permanent")
|
||||
}
|
||||
}
|
||||
|
||||
func TestAttackBanDoesNotLengthenTheNextBanForALimit(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
|
||||
Reference in New Issue
Block a user