Reputation from AbuseIPDB, as "Reputation" in SPEC.md gives it. Built after the DNS blocklists (#104), whose verdict cache, SWWAF_REPUTATION_ACTION and reputation.json it shares. One PR to next.
SWWAF_ABUSEIPDB_KEY, SWWAF_ABUSEIPDB_MIN_SCORE (default 75), SWWAF_ABUSEIPDB_DAILY_BUDGET (default 900). Only a client that has already committed one offence is queried, in the background, so the budget is spent on suspects; the checks spent today kept in reputation.json, so a restart does not reset the budget.
A score at or over the minimum is a hit, applied by SWWAF_REPUTATION_ACTION; the budget used up, a refusal or a failure gives no verdict and one source_failure alert per cooldown. The key never printed.
The request log's reputation, a reputation_hit alert and metrics (checks spent, budget left) as "Metrics endpoint" gives them; README.md documents it.
Definition of done: tests, against a local stand-in on a clock the test controls, show only offenders queried, the score threshold, the daily budget kept across a restart and reset at the day's end, a failure, and the key never printed; each test failing with its rule broken; make check green; one PR to next, passed by a reviewer who did not write it.
Model: opus-5-5
Reputation from AbuseIPDB, as "Reputation" in `SPEC.md` gives it. Built after the DNS blocklists (https://git.eeqj.de/sneak/smallwebwaf/issues/104), whose verdict cache, `SWWAF_REPUTATION_ACTION` and `reputation.json` it shares. One PR to `next`.
- `SWWAF_ABUSEIPDB_KEY`, `SWWAF_ABUSEIPDB_MIN_SCORE` (default `75`), `SWWAF_ABUSEIPDB_DAILY_BUDGET` (default `900`). Only a client that has already committed one offence is queried, in the background, so the budget is spent on suspects; the checks spent today kept in `reputation.json`, so a restart does not reset the budget.
- A score at or over the minimum is a hit, applied by `SWWAF_REPUTATION_ACTION`; the budget used up, a refusal or a failure gives no verdict and one `source_failure` alert per cooldown. The key never printed.
- The request log's `reputation`, a `reputation_hit` alert and metrics (checks spent, budget left) as "Metrics endpoint" gives them; `README.md` documents it.
Definition of done: tests, against a local stand-in on a clock the test controls, show only offenders queried, the score threshold, the daily budget kept across a restart and reset at the day's end, a failure, and the key never printed; each test failing with its rule broken; `make check` green; one PR to `next`, passed by a reviewer who did not write it.
Model: opus-5-5
clawbot
self-assigned this 2026-10-07 14:23:11 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Reputation from AbuseIPDB, as "Reputation" in
SPEC.mdgives it. Built after the DNS blocklists (#104), whose verdict cache,SWWAF_REPUTATION_ACTIONandreputation.jsonit shares. One PR tonext.SWWAF_ABUSEIPDB_KEY,SWWAF_ABUSEIPDB_MIN_SCORE(default75),SWWAF_ABUSEIPDB_DAILY_BUDGET(default900). Only a client that has already committed one offence is queried, in the background, so the budget is spent on suspects; the checks spent today kept inreputation.json, so a restart does not reset the budget.SWWAF_REPUTATION_ACTION; the budget used up, a refusal or a failure gives no verdict and onesource_failurealert per cooldown. The key never printed.reputation, areputation_hitalert and metrics (checks spent, budget left) as "Metrics endpoint" gives them;README.mddocuments it.Definition of done: tests, against a local stand-in on a clock the test controls, show only offenders queried, the score threshold, the daily budget kept across a restart and reset at the day's end, a failure, and the key never printed; each test failing with its rule broken;
make checkgreen; one PR tonext, passed by a reviewer who did not write it.Model: opus-5-5
Implemented in #111.
Model: opus-5-5