Network lists: always allowed, exempt from rate limits, always refused #66

Merged
clawbot merged 1 commits from issue-19-network-lists into next 2026-10-06 02:36:28 +02:00
Collaborator

Implements #19 as planned in #19 (comment).

  • SWWAF_ALLOW_NETS, SWWAF_RATE_LIMIT_EXEMPT_NETS and SWWAF_DENY_NETS are read by the same code as SWWAF_TRUSTED_PROXIES and are empty by default. An entry that does not parse stops the start, and the message names the setting.
  • The proxy's check method compares the client's own address with these lists before anything else. A client in SWWAF_ALLOW_NETS skips SWWAF_DENY_NETS, the country lists and the rate limits, and its country is not looked up. A client in SWWAF_DENY_NETS is refused with 403 before its body is read and before the lookup. The request is logged as denied and not counted for the rate limits. The rate limits neither count nor refuse a client in SWWAF_RATE_LIMIT_EXEMPT_NETS, but the country lists still apply to it.
  • SWWAF_EXCLUSIVELY_ALLOWED_COUNTRIES now refuses a private, loopback or link-local client unless SWWAF_ALLOW_NETS lists it. SWWAF_DENIED_COUNTRIES still lets such a client through, and its address still never goes to GeoJS.
  • README.md documents all of this.

Not visible in the diff: the lists match single addresses, but the rate limits count an IPv6 client by its /64. The tests use that to show that a denied or exempt request is not counted.

  • Judgement call: an address in both SWWAF_ALLOW_NETS and SWWAF_DENY_NETS is let through, because SPEC.md checks the allow list first.
  • Judgement call: SWWAF_ALLOW_NETS clients are still held to the size and time limits, which SPEC.md applies to every request.
  • The new proxy tests use the real clock, as the existing proxy tests do. None waits for time to pass.

Model: opus-5-5

Implements https://git.eeqj.de/sneak/smallwebwaf/issues/19 as planned in https://git.eeqj.de/sneak/smallwebwaf/issues/19#issuecomment-126850. - `SWWAF_ALLOW_NETS`, `SWWAF_RATE_LIMIT_EXEMPT_NETS` and `SWWAF_DENY_NETS` are read by the same code as `SWWAF_TRUSTED_PROXIES` and are empty by default. An entry that does not parse stops the start, and the message names the setting. - The proxy's `check` method compares the client's own address with these lists before anything else. A client in `SWWAF_ALLOW_NETS` skips `SWWAF_DENY_NETS`, the country lists and the rate limits, and its country is not looked up. A client in `SWWAF_DENY_NETS` is refused with `403` before its body is read and before the lookup. The request is logged as `denied` and not counted for the rate limits. The rate limits neither count nor refuse a client in `SWWAF_RATE_LIMIT_EXEMPT_NETS`, but the country lists still apply to it. - `SWWAF_EXCLUSIVELY_ALLOWED_COUNTRIES` now refuses a private, loopback or link-local client unless `SWWAF_ALLOW_NETS` lists it. `SWWAF_DENIED_COUNTRIES` still lets such a client through, and its address still never goes to GeoJS. - `README.md` documents all of this. Not visible in the diff: the lists match single addresses, but the rate limits count an IPv6 client by its /64. The tests use that to show that a denied or exempt request is not counted. - Judgement call: an address in both `SWWAF_ALLOW_NETS` and `SWWAF_DENY_NETS` is let through, because `SPEC.md` checks the allow list first. - Judgement call: `SWWAF_ALLOW_NETS` clients are still held to the size and time limits, which `SPEC.md` applies to every request. - The new proxy tests use the real clock, as the existing proxy tests do. None waits for time to pass. Model: opus-5-5
clawbot self-assigned this 2026-10-06 01:36:11 +02:00
clawbot added the needs-review label 2026-10-06 01:36:15 +02:00
Author
Collaborator

Review failed: one finding.

  • internal/proxy/staticlists_test.go, TestAllowNetsSkipEveryCheckButTheSizeLimit: no test shows that a request from a client in SWWAF_ALLOW_NETS is left out of the rate limits' counts. The test shows only that such a client is not refused. If the code counted these requests, an unlisted address in the same IPv6 /64 could be pushed over a limit, and every test would still pass. A likely place for that to break is the later work that counts allowed clients for anomaly alerts. Acceptable: a case like the ones for SWWAF_DENY_NETS and SWWAF_RATE_LIMIT_EXEMPT_NETS, where an allowed address sends requests over the limit and an unlisted address in its /64 still gets its full allowance.

Judgement calls accepted: an address in both SWWAF_ALLOW_NETS and SWWAF_DENY_NETS is let through; SWWAF_ALLOW_NETS clients are still held to the size and time limits.

Model: opus-5-5

Review failed: one finding. - `internal/proxy/staticlists_test.go`, `TestAllowNetsSkipEveryCheckButTheSizeLimit`: no test shows that a request from a client in `SWWAF_ALLOW_NETS` is left out of the rate limits' counts. The test shows only that such a client is not refused. If the code counted these requests, an unlisted address in the same IPv6 /64 could be pushed over a limit, and every test would still pass. A likely place for that to break is the later work that counts allowed clients for anomaly alerts. Acceptable: a case like the ones for `SWWAF_DENY_NETS` and `SWWAF_RATE_LIMIT_EXEMPT_NETS`, where an allowed address sends requests over the limit and an unlisted address in its /64 still gets its full allowance. Judgement calls accepted: an address in both `SWWAF_ALLOW_NETS` and `SWWAF_DENY_NETS` is let through; `SWWAF_ALLOW_NETS` clients are still held to the size and time limits. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-06 02:01:15 +02:00
clawbot added 1 commit 2026-10-06 02:06:16 +02:00
Adds SWWAF_ALLOW_NETS, SWWAF_RATE_LIMIT_EXEMPT_NETS and SWWAF_DENY_NETS,
read like SWWAF_TRUSTED_PROXIES and empty by default, and checked against
the client's own address before its country is looked up. A client in
SWWAF_ALLOW_NETS skips the country lists and the rate limits and is not
looked up. One in SWWAF_DENY_NETS is refused with 403, logged as denied
and not counted. One in SWWAF_RATE_LIMIT_EXEMPT_NETS is neither counted
nor refused by the rate limits. SWWAF_EXCLUSIVELY_ALLOWED_COUNTRIES now
refuses a private, loopback or link-local client unless SWWAF_ALLOW_NETS
lists it.

Judgement call: an address in both SWWAF_ALLOW_NETS and SWWAF_DENY_NETS is let through.
Judgement call: the size and time limits still apply to SWWAF_ALLOW_NETS.

Model: opus-5-5
clawbot force-pushed issue-19-network-lists from c6070bf792 to e001f1c830 2026-10-06 02:06:16 +02:00 Compare
Author
Collaborator

Added a test in which an address in SWWAF_ALLOW_NETS sends requests over the limit and an unlisted address in its IPv6 /64 still gets its full allowance; reworded the doc comment on wantAnswers.

Model: opus-5-5

Added a test in which an address in `SWWAF_ALLOW_NETS` sends requests over the limit and an unlisted address in its IPv6 /64 still gets its full allowance; reworded the doc comment on `wantAnswers`. Model: opus-5-5
clawbot added needs-review and removed needs-rework labels 2026-10-06 02:06:26 +02:00
Author
Collaborator

Review passed.

  • Judgement call accepted: an address in both SWWAF_ALLOW_NETS and SWWAF_DENY_NETS is let through.
  • Judgement call accepted: clients in SWWAF_ALLOW_NETS are still held to the size and time limits.
  • Judgement call accepted: the new proxy tests use the real clock, as the existing proxy tests do.
  • Judgement call accepted: the lists match single addresses while the rate limits count an IPv6 client by its /64, and the tests use a second address in the same /64 to show that a request is not counted.

Model: opus-5-5

Review passed. - Judgement call accepted: an address in both `SWWAF_ALLOW_NETS` and `SWWAF_DENY_NETS` is let through. - Judgement call accepted: clients in `SWWAF_ALLOW_NETS` are still held to the size and time limits. - Judgement call accepted: the new proxy tests use the real clock, as the existing proxy tests do. - Judgement call accepted: the lists match single addresses while the rate limits count an IPv6 client by its /64, and the tests use a second address in the same /64 to show that a request is not counted. Model: opus-5-5
clawbot merged commit 7f6f89cd83 into next 2026-10-06 02:36:28 +02:00
clawbot deleted branch issue-19-network-lists 2026-10-06 02:36:29 +02:00
clawbot removed the needs-review label 2026-10-06 02:36:29 +02:00
Sign in to join this conversation.