Ban notes name the reputation sources that listed the client #114

Merged
clawbot merged 1 commits from issue-109-notes-reputation into next 2026-10-08 03:08:01 +02:00
Collaborator

Builds #109.

  • A ban's notes gain reputation: each blocklist, DNSBL zone or AbuseIPDB that listed the client when the ban was made, as its source, named and ordered as in the request log's reputation, with AbuseIPDB's score of the client. It is left out when none did. Bans for a broken rate limit or byte limit and for a clear sign of attack get it, in observe mode too, and the alert for the ban carries it, since its notes are the ban's.
  • The reputation_hit alert's detail is now built from the same value; its form is unchanged.
  • README.md: the list of what the notes hold, the bans.json entry, a bans.json example of a ban with a DNSBL zone and AbuseIPDB in its notes, and the two places that list where a blocklist's URL or a zone's name is shown now name the notes of bans too.

Easy to miss: Notes now holds a list, so Ban and Notes can no longer be compared with ==; the tests that did so use reflect.DeepEqual, and the state tests' wantEqual takes any type.

Judgement call: score is a pointer, so a score of 0, a hit while SWWAF_ABUSEIPDB_MIN_SCORE is 0, is still written.
Judgement call: the sources' names are kept whole, not cut to 256 bytes as the request's texts are; they come from the settings.

Model: opus-5-5

Builds https://git.eeqj.de/sneak/smallwebwaf/issues/109. - A ban's notes gain `reputation`: each blocklist, DNSBL zone or AbuseIPDB that listed the client when the ban was made, as its `source`, named and ordered as in the request log's `reputation`, with AbuseIPDB's `score` of the client. It is left out when none did. Bans for a broken rate limit or byte limit and for a clear sign of attack get it, in `observe` mode too, and the alert for the ban carries it, since its `notes` are the ban's. - The `reputation_hit` alert's detail is now built from the same value; its form is unchanged. - `README.md`: the list of what the notes hold, the `bans.json` entry, a `bans.json` example of a ban with a DNSBL zone and AbuseIPDB in its notes, and the two places that list where a blocklist's URL or a zone's name is shown now name the notes of bans too. Easy to miss: `Notes` now holds a list, so `Ban` and `Notes` can no longer be compared with `==`; the tests that did so use `reflect.DeepEqual`, and the state tests' `wantEqual` takes any type. Judgement call: `score` is a pointer, so a score of 0, a hit while `SWWAF_ABUSEIPDB_MIN_SCORE` is 0, is still written. Judgement call: the sources' names are kept whole, not cut to 256 bytes as the request's texts are; they come from the settings. Model: opus-5-5
clawbot added the needs-review label 2026-10-08 02:40:33 +02:00
clawbot self-assigned this 2026-10-08 02:40:33 +02:00
clawbot added 1 commit 2026-10-08 02:40:34 +02:00
A ban's notes, in bans.json and in its alert, gain `reputation`: each
blocklist, DNSBL zone or AbuseIPDB that listed the client when the ban
was made, as its `source`, named and ordered as in the request log's
`reputation`, with AbuseIPDB's `score`. It is left out when none did.
README.md shows it in a bans.json example.

Notes now hold a list, so bans can no longer be compared with ==: the
tests compare them with reflect.DeepEqual.

Judgement call: the score is a pointer, so a score of 0, a hit while
SWWAF_ABUSEIPDB_MIN_SCORE is 0, is still written.

Model: opus-5-5
Author
Collaborator

Review passed.

Judgement call accepted: score is a pointer, so a score of 0 is still written.
Judgement call accepted: the sources' names are kept whole, not cut to 256 bytes, since they come from the settings.

Model: opus-5-5

Review passed. Judgement call accepted: `score` is a pointer, so a score of 0 is still written. Judgement call accepted: the sources' names are kept whole, not cut to 256 bytes, since they come from the settings. Model: opus-5-5
clawbot merged commit 04e66d2069 into next 2026-10-08 03:08:01 +02:00
clawbot deleted branch issue-109-notes-reputation 2026-10-08 03:08:02 +02:00
Sign in to join this conversation.