Milestone 2, part 2: country allow and deny lists, with GeoJS lookup #44

Open
opened 2026-10-04 02:44:50 +02:00 by clawbot · 1 comment
Collaborator

Part 2 of 3 of milestone 2, #14. The order of the three parts is on that issue's plan comment. One PR to next, after part 1 is on next.

What it builds

The country lists and the GeoJS lookup of issue 14 ("Country lists" and "Country lookup through GeoJS" under "What it adds", and the two country settings), as SPEC.md describes them:

  • SWWAF_DENIED_COUNTRIES refuses a request from a listed country; SWWAF_EXCLUSIVELY_ALLOWED_COUNTRIES refuses one from any other country and one whose country cannot be found. Both empty by default.
  • A refused request gets 403 as soon as the client's country is known, before its body is read; it skips the rate limits and is logged with the action country_denied and its country. Every log line gains country.
  • Codes are two-letter ISO codes in either case. An unknown code stops the start with a message naming it; a code on both lists stops the start.
  • A client on a private, loopback or link-local address has no country: neither list checks it, and its address is never sent to GeoJS.
  • GeoJS is asked only while a country list is set. Each answer is kept in memory for 7 days; at most 100,000 answers, the least recently seen dropped first.
  • A new client waits at most one second for its answer, and without one counts as a client whose country cannot be found until the answer arrives.
  • At most one request to GeoJS at a time, carrying every address waiting.
  • While GeoJS fails, clients with a kept answer are unaffected, new ones count as not found, and GeoJS is asked again with backoff.
  • README.md documents the two settings and that visitors' addresses go to GeoJS only while a list is set.

Not in this part: the image and /_smallwebwaf/healthz (part 3), anything written to disk.

Definition of done

  • Tests show: both lists; a client whose country cannot be found; one on a private address; no lookup while neither list is set; a kept answer used without asking GeoJS again, and asked again after 7 days; several waiting addresses sent in one request; GeoJS failing and being asked again with backoff; each setting's default and the start refused for invalid values. The tests use a local stand-in for GeoJS and a clock the test controls; none calls the real service.
  • make check green; one PR to next, passed by a reviewer who did not write it; the landing commit title ends with this issue's (closes #N).

Model: opus-5-5

Part 2 of 3 of milestone 2, https://git.eeqj.de/sneak/smallwebwaf/issues/14. The order of the three parts is on that issue's plan comment. One PR to `next`, after part 1 is on `next`. ## What it builds The country lists and the GeoJS lookup of issue 14 ("Country lists" and "Country lookup through GeoJS" under "What it adds", and the two country settings), as `SPEC.md` describes them: - `SWWAF_DENIED_COUNTRIES` refuses a request from a listed country; `SWWAF_EXCLUSIVELY_ALLOWED_COUNTRIES` refuses one from any other country and one whose country cannot be found. Both empty by default. - A refused request gets `403` as soon as the client's country is known, before its body is read; it skips the rate limits and is logged with the `action` `country_denied` and its country. Every log line gains `country`. - Codes are two-letter ISO codes in either case. An unknown code stops the start with a message naming it; a code on both lists stops the start. - A client on a private, loopback or link-local address has no country: neither list checks it, and its address is never sent to GeoJS. - GeoJS is asked only while a country list is set. Each answer is kept in memory for 7 days; at most 100,000 answers, the least recently seen dropped first. - A new client waits at most one second for its answer, and without one counts as a client whose country cannot be found until the answer arrives. - At most one request to GeoJS at a time, carrying every address waiting. - While GeoJS fails, clients with a kept answer are unaffected, new ones count as not found, and GeoJS is asked again with backoff. - `README.md` documents the two settings and that visitors' addresses go to GeoJS only while a list is set. Not in this part: the image and `/_smallwebwaf/healthz` (part 3), anything written to disk. ## Definition of done - Tests show: both lists; a client whose country cannot be found; one on a private address; no lookup while neither list is set; a kept answer used without asking GeoJS again, and asked again after 7 days; several waiting addresses sent in one request; GeoJS failing and being asked again with backoff; each setting's default and the start refused for invalid values. The tests use a local stand-in for GeoJS and a clock the test controls; none calls the real service. - `make check` green; one PR to `next`, passed by a reviewer who did not write it; the landing commit title ends with this issue's ` (closes #N)`. Model: opus-5-5
clawbot self-assigned this 2026-10-04 02:44:50 +02:00
Author
Collaborator

Built in #54, for review.

Model: opus-5-5

Built in https://git.eeqj.de/sneak/smallwebwaf/pulls/54, for review. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/smallwebwaf#44