Part 2 of 3 of milestone 2, #14. The order of the three parts is on that issue's plan comment. One PR to next, after part 1 is on next.
What it builds
The country lists and the GeoJS lookup of issue 14 ("Country lists" and "Country lookup through GeoJS" under "What it adds", and the two country settings), as SPEC.md describes them:
SWWAF_DENIED_COUNTRIES refuses a request from a listed country; SWWAF_EXCLUSIVELY_ALLOWED_COUNTRIES refuses one from any other country and one whose country cannot be found. Both empty by default.
A refused request gets 403 as soon as the client's country is known, before its body is read; it skips the rate limits and is logged with the actioncountry_denied and its country. Every log line gains country.
Codes are two-letter ISO codes in either case. An unknown code stops the start with a message naming it; a code on both lists stops the start.
A client on a private, loopback or link-local address has no country: neither list checks it, and its address is never sent to GeoJS.
GeoJS is asked only while a country list is set. Each answer is kept in memory for 7 days; at most 100,000 answers, the least recently seen dropped first.
A new client waits at most one second for its answer, and without one counts as a client whose country cannot be found until the answer arrives.
At most one request to GeoJS at a time, carrying every address waiting.
While GeoJS fails, clients with a kept answer are unaffected, new ones count as not found, and GeoJS is asked again with backoff.
README.md documents the two settings and that visitors' addresses go to GeoJS only while a list is set.
Not in this part: the image and /_smallwebwaf/healthz (part 3), anything written to disk.
Definition of done
Tests show: both lists; a client whose country cannot be found; one on a private address; no lookup while neither list is set; a kept answer used without asking GeoJS again, and asked again after 7 days; several waiting addresses sent in one request; GeoJS failing and being asked again with backoff; each setting's default and the start refused for invalid values. The tests use a local stand-in for GeoJS and a clock the test controls; none calls the real service.
make check green; one PR to next, passed by a reviewer who did not write it; the landing commit title ends with this issue's (closes #N).
Model: opus-5-5
Part 2 of 3 of milestone 2, https://git.eeqj.de/sneak/smallwebwaf/issues/14. The order of the three parts is on that issue's plan comment. One PR to `next`, after part 1 is on `next`.
## What it builds
The country lists and the GeoJS lookup of issue 14 ("Country lists" and "Country lookup through GeoJS" under "What it adds", and the two country settings), as `SPEC.md` describes them:
- `SWWAF_DENIED_COUNTRIES` refuses a request from a listed country; `SWWAF_EXCLUSIVELY_ALLOWED_COUNTRIES` refuses one from any other country and one whose country cannot be found. Both empty by default.
- A refused request gets `403` as soon as the client's country is known, before its body is read; it skips the rate limits and is logged with the `action` `country_denied` and its country. Every log line gains `country`.
- Codes are two-letter ISO codes in either case. An unknown code stops the start with a message naming it; a code on both lists stops the start.
- A client on a private, loopback or link-local address has no country: neither list checks it, and its address is never sent to GeoJS.
- GeoJS is asked only while a country list is set. Each answer is kept in memory for 7 days; at most 100,000 answers, the least recently seen dropped first.
- A new client waits at most one second for its answer, and without one counts as a client whose country cannot be found until the answer arrives.
- At most one request to GeoJS at a time, carrying every address waiting.
- While GeoJS fails, clients with a kept answer are unaffected, new ones count as not found, and GeoJS is asked again with backoff.
- `README.md` documents the two settings and that visitors' addresses go to GeoJS only while a list is set.
Not in this part: the image and `/_smallwebwaf/healthz` (part 3), anything written to disk.
## Definition of done
- Tests show: both lists; a client whose country cannot be found; one on a private address; no lookup while neither list is set; a kept answer used without asking GeoJS again, and asked again after 7 days; several waiting addresses sent in one request; GeoJS failing and being asked again with backoff; each setting's default and the start refused for invalid values. The tests use a local stand-in for GeoJS and a clock the test controls; none calls the real service.
- `make check` green; one PR to `next`, passed by a reviewer who did not write it; the landing commit title ends with this issue's ` (closes #N)`.
Model: opus-5-5
clawbot
self-assigned this 2026-10-04 02:44:50 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Part 2 of 3 of milestone 2, #14. The order of the three parts is on that issue's plan comment. One PR to
next, after part 1 is onnext.What it builds
The country lists and the GeoJS lookup of issue 14 ("Country lists" and "Country lookup through GeoJS" under "What it adds", and the two country settings), as
SPEC.mddescribes them:SWWAF_DENIED_COUNTRIESrefuses a request from a listed country;SWWAF_EXCLUSIVELY_ALLOWED_COUNTRIESrefuses one from any other country and one whose country cannot be found. Both empty by default.403as soon as the client's country is known, before its body is read; it skips the rate limits and is logged with theactioncountry_deniedand its country. Every log line gainscountry.README.mddocuments the two settings and that visitors' addresses go to GeoJS only while a list is set.Not in this part: the image and
/_smallwebwaf/healthz(part 3), anything written to disk.Definition of done
make checkgreen; one PR tonext, passed by a reviewer who did not write it; the landing commit title ends with this issue's(closes #N).Model: opus-5-5
Built in #54, for review.
Model: opus-5-5
clawbot referenced this issue2026-10-04 08:30:15 +02:00