requirement: very simple way to entirely block a list of countries, or to allow only certain countries #8

Closed
opened 2026-09-23 14:45:49 +02:00 by sneak · 3 comments
Owner

eg:

EXCLUSIVELY_ALLOWED_COUNTRIES="us,de" # blocks all geoip countries except these

DENIED_COUNTRIES="cn,ru,nk,ir,ua,by" # immediate deny based on source country

eg: `EXCLUSIVELY_ALLOWED_COUNTRIES="us,de" # blocks all geoip countries except these` `DENIED_COUNTRIES="cn,ru,nk,ir,ua,by" # immediate deny based on source country`
Author
Owner

when a request is blocked by one of these, no waf or ruleset matching is required. put it in metrics and move on. this can happen even before reading the request body, as soon as we see the client IP. i'd say just drop the connections but traefik will give 5xx then i assume, so respond with a 403 or 429 or whatever we're using to deny banned hosts.

when a request is blocked by one of these, no waf or ruleset matching is required. put it in metrics and move on. this can happen even before reading the request body, as soon as we see the client IP. i'd say just drop the connections but traefik will give 5xx then i assume, so respond with a 403 or 429 or whatever we're using to deny banned hosts.
Collaborator

Folded into the spec update, #9, which will close this issue. The spec adds EXCLUSIVELY_ALLOWED_COUNTRIES and DENIED_COUNTRIES as you wrote them: a request from a denied country, or, when the exclusive list is set, from any country not on it, is refused as soon as the client address is known, before the body is read. It skips the rule files and the Core Rule Set, is counted in the metrics, and gets the same answer as a banned client (BAN_RESPONSE, 403 by default). Both lists need the lookup database, so setting either without it stops the start. North Korea's code is kp; nk is not a country code, and an unknown code stops the start with a message naming it rather than blocking nothing.

Model: opus-5-5

Folded into the spec update, https://git.eeqj.de/sneak/smallwebwaf/pulls/9, which will close this issue. The spec adds `EXCLUSIVELY_ALLOWED_COUNTRIES` and `DENIED_COUNTRIES` as you wrote them: a request from a denied country, or, when the exclusive list is set, from any country not on it, is refused as soon as the client address is known, before the body is read. It skips the rule files and the Core Rule Set, is counted in the metrics, and gets the same answer as a banned client (`BAN_RESPONSE`, 403 by default). Both lists need the lookup database, so setting either without it stops the start. North Korea's code is `kp`; `nk` is not a country code, and an unknown code stops the start with a message naming it rather than blocking nothing. Model: opus-5-5
clawbot self-assigned this 2026-09-23 15:00:18 +02:00
Collaborator

Closed by the merge of #9 into next (commit 7898957).

Model: opus-5-5

Closed by the merge of https://git.eeqj.de/sneak/smallwebwaf/pulls/9 into `next` (commit `7898957`). Model: opus-5-5
Sign in to join this conversation.
2 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/smallwebwaf#8