The optional CrowdSec decision feed, as "Reputation" in SPEC.md gives it. Built after the downloaded blocklists (#29), whose fetching and keeping it shares. One PR to next.
SWWAF_CROWDSEC_LAPI_URL, SWWAF_CROWDSEC_LAPI_KEY: the engine's decision list pulled on a schedule and kept like a fetched blocklist (last good copy on failure and across restarts). The key never printed.
A listed client's request makes a ban with the cause crowdsec that lasts as long as CrowdSec's decision, so a long list does not fill bans.json; crowdsec becomes an accepted cause in bans.json and the ban notes.
A failing or refusing engine sends one source_failure alert per cooldown; metrics as "Metrics endpoint" gives them; README.md documents it.
Definition of done: tests, against a local stand-in for the engine on a clock the test controls, show a listed client banned with the cause crowdsec for the decision's length, the list kept across a restart and on failure, an expired decision no longer banning, and the key never printed; each test failing with its rule broken; make check green; one PR to next, passed by a reviewer who did not write it.
Model: opus-5-5
The optional CrowdSec decision feed, as "Reputation" in `SPEC.md` gives it. Built after the downloaded blocklists (https://git.eeqj.de/sneak/smallwebwaf/issues/29), whose fetching and keeping it shares. One PR to `next`.
- `SWWAF_CROWDSEC_LAPI_URL`, `SWWAF_CROWDSEC_LAPI_KEY`: the engine's decision list pulled on a schedule and kept like a fetched blocklist (last good copy on failure and across restarts). The key never printed.
- A listed client's request makes a ban with the cause `crowdsec` that lasts as long as CrowdSec's decision, so a long list does not fill `bans.json`; `crowdsec` becomes an accepted cause in `bans.json` and the ban notes.
- A failing or refusing engine sends one `source_failure` alert per cooldown; metrics as "Metrics endpoint" gives them; `README.md` documents it.
Definition of done: tests, against a local stand-in for the engine on a clock the test controls, show a listed client banned with the cause `crowdsec` for the decision's length, the list kept across a restart and on failure, an expired decision no longer banning, and the key never printed; each test failing with its rule broken; `make check` green; one PR to `next`, passed by a reviewer who did not write it.
Model: opus-5-5
clawbot
self-assigned this 2026-10-07 14:23:11 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The optional CrowdSec decision feed, as "Reputation" in
SPEC.mdgives it. Built after the downloaded blocklists (#29), whose fetching and keeping it shares. One PR tonext.SWWAF_CROWDSEC_LAPI_URL,SWWAF_CROWDSEC_LAPI_KEY: the engine's decision list pulled on a schedule and kept like a fetched blocklist (last good copy on failure and across restarts). The key never printed.crowdsecthat lasts as long as CrowdSec's decision, so a long list does not fillbans.json;crowdsecbecomes an accepted cause inbans.jsonand the ban notes.source_failurealert per cooldown; metrics as "Metrics endpoint" gives them;README.mddocuments it.Definition of done: tests, against a local stand-in for the engine on a clock the test controls, show a listed client banned with the cause
crowdsecfor the decision's length, the list kept across a restart and on failure, an expired decision no longer banning, and the key never printed; each test failing with its rule broken;make checkgreen; one PR tonext, passed by a reviewer who did not write it.Model: opus-5-5
Implemented in #117, awaiting review.
Model: opus-5-5