SWWAF_ALLOW_NETS, SWWAF_RATE_LIMIT_EXEMPT_NETS and SWWAF_DENY_NETS are read by the same code as SWWAF_TRUSTED_PROXIES and are empty by default. An entry that does not parse stops the start, and the message names the setting.
The proxy's check method compares the client's own address with these lists before anything else. A client in SWWAF_ALLOW_NETS skips SWWAF_DENY_NETS, the country lists and the rate limits, and its country is not looked up. A client in SWWAF_DENY_NETS is refused with 403 before its body is read and before the lookup. The request is logged as denied and not counted for the rate limits. The rate limits neither count nor refuse a client in SWWAF_RATE_LIMIT_EXEMPT_NETS, but the country lists still apply to it.
SWWAF_EXCLUSIVELY_ALLOWED_COUNTRIES now refuses a private, loopback or link-local client unless SWWAF_ALLOW_NETS lists it. SWWAF_DENIED_COUNTRIES still lets such a client through, and its address still never goes to GeoJS.
README.md documents all of this.
Not visible in the diff: the lists match single addresses, but the rate limits count an IPv6 client by its /64. The tests use that to show that a denied or exempt request is not counted.
Judgement call: an address in both SWWAF_ALLOW_NETS and SWWAF_DENY_NETS is let through, because SPEC.md checks the allow list first.
Judgement call: SWWAF_ALLOW_NETS clients are still held to the size and time limits, which SPEC.md applies to every request.
The new proxy tests use the real clock, as the existing proxy tests do. None waits for time to pass.
Model: opus-5-5
Implements https://git.eeqj.de/sneak/smallwebwaf/issues/19 as planned in https://git.eeqj.de/sneak/smallwebwaf/issues/19#issuecomment-126850.
- `SWWAF_ALLOW_NETS`, `SWWAF_RATE_LIMIT_EXEMPT_NETS` and `SWWAF_DENY_NETS` are read by the same code as `SWWAF_TRUSTED_PROXIES` and are empty by default. An entry that does not parse stops the start, and the message names the setting.
- The proxy's `check` method compares the client's own address with these lists before anything else. A client in `SWWAF_ALLOW_NETS` skips `SWWAF_DENY_NETS`, the country lists and the rate limits, and its country is not looked up. A client in `SWWAF_DENY_NETS` is refused with `403` before its body is read and before the lookup. The request is logged as `denied` and not counted for the rate limits. The rate limits neither count nor refuse a client in `SWWAF_RATE_LIMIT_EXEMPT_NETS`, but the country lists still apply to it.
- `SWWAF_EXCLUSIVELY_ALLOWED_COUNTRIES` now refuses a private, loopback or link-local client unless `SWWAF_ALLOW_NETS` lists it. `SWWAF_DENIED_COUNTRIES` still lets such a client through, and its address still never goes to GeoJS.
- `README.md` documents all of this.
Not visible in the diff: the lists match single addresses, but the rate limits count an IPv6 client by its /64. The tests use that to show that a denied or exempt request is not counted.
- Judgement call: an address in both `SWWAF_ALLOW_NETS` and `SWWAF_DENY_NETS` is let through, because `SPEC.md` checks the allow list first.
- Judgement call: `SWWAF_ALLOW_NETS` clients are still held to the size and time limits, which `SPEC.md` applies to every request.
- The new proxy tests use the real clock, as the existing proxy tests do. None waits for time to pass.
Model: opus-5-5
clawbot
self-assigned this 2026-10-06 01:36:11 +02:00
internal/proxy/staticlists_test.go, TestAllowNetsSkipEveryCheckButTheSizeLimit: no test shows that a request from a client in SWWAF_ALLOW_NETS is left out of the rate limits' counts. The test shows only that such a client is not refused. If the code counted these requests, an unlisted address in the same IPv6 /64 could be pushed over a limit, and every test would still pass. A likely place for that to break is the later work that counts allowed clients for anomaly alerts. Acceptable: a case like the ones for SWWAF_DENY_NETS and SWWAF_RATE_LIMIT_EXEMPT_NETS, where an allowed address sends requests over the limit and an unlisted address in its /64 still gets its full allowance.
Judgement calls accepted: an address in both SWWAF_ALLOW_NETS and SWWAF_DENY_NETS is let through; SWWAF_ALLOW_NETS clients are still held to the size and time limits.
Model: opus-5-5
Review failed: one finding.
- `internal/proxy/staticlists_test.go`, `TestAllowNetsSkipEveryCheckButTheSizeLimit`: no test shows that a request from a client in `SWWAF_ALLOW_NETS` is left out of the rate limits' counts. The test shows only that such a client is not refused. If the code counted these requests, an unlisted address in the same IPv6 /64 could be pushed over a limit, and every test would still pass. A likely place for that to break is the later work that counts allowed clients for anomaly alerts. Acceptable: a case like the ones for `SWWAF_DENY_NETS` and `SWWAF_RATE_LIMIT_EXEMPT_NETS`, where an allowed address sends requests over the limit and an unlisted address in its /64 still gets its full allowance.
Judgement calls accepted: an address in both `SWWAF_ALLOW_NETS` and `SWWAF_DENY_NETS` is let through; `SWWAF_ALLOW_NETS` clients are still held to the size and time limits.
Model: opus-5-5
Adds SWWAF_ALLOW_NETS, SWWAF_RATE_LIMIT_EXEMPT_NETS and SWWAF_DENY_NETS,
read like SWWAF_TRUSTED_PROXIES and empty by default, and checked against
the client's own address before its country is looked up. A client in
SWWAF_ALLOW_NETS skips the country lists and the rate limits and is not
looked up. One in SWWAF_DENY_NETS is refused with 403, logged as denied
and not counted. One in SWWAF_RATE_LIMIT_EXEMPT_NETS is neither counted
nor refused by the rate limits. SWWAF_EXCLUSIVELY_ALLOWED_COUNTRIES now
refuses a private, loopback or link-local client unless SWWAF_ALLOW_NETS
lists it.
Judgement call: an address in both SWWAF_ALLOW_NETS and SWWAF_DENY_NETS is let through.
Judgement call: the size and time limits still apply to SWWAF_ALLOW_NETS.
Model: opus-5-5
Added a test in which an address in SWWAF_ALLOW_NETS sends requests over the limit and an unlisted address in its IPv6 /64 still gets its full allowance; reworded the doc comment on wantAnswers.
Model: opus-5-5
Added a test in which an address in `SWWAF_ALLOW_NETS` sends requests over the limit and an unlisted address in its IPv6 /64 still gets its full allowance; reworded the doc comment on `wantAnswers`.
Model: opus-5-5
Judgement call accepted: an address in both SWWAF_ALLOW_NETS and SWWAF_DENY_NETS is let through.
Judgement call accepted: clients in SWWAF_ALLOW_NETS are still held to the size and time limits.
Judgement call accepted: the new proxy tests use the real clock, as the existing proxy tests do.
Judgement call accepted: the lists match single addresses while the rate limits count an IPv6 client by its /64, and the tests use a second address in the same /64 to show that a request is not counted.
Model: opus-5-5
Review passed.
- Judgement call accepted: an address in both `SWWAF_ALLOW_NETS` and `SWWAF_DENY_NETS` is let through.
- Judgement call accepted: clients in `SWWAF_ALLOW_NETS` are still held to the size and time limits.
- Judgement call accepted: the new proxy tests use the real clock, as the existing proxy tests do.
- Judgement call accepted: the lists match single addresses while the rate limits count an IPv6 client by its /64, and the tests use a second address in the same /64 to show that a request is not counted.
Model: opus-5-5
clawbot
merged commit 7f6f89cd83 into next2026-10-06 02:36:28 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Implements #19 as planned in #19 (comment).
SWWAF_ALLOW_NETS,SWWAF_RATE_LIMIT_EXEMPT_NETSandSWWAF_DENY_NETSare read by the same code asSWWAF_TRUSTED_PROXIESand are empty by default. An entry that does not parse stops the start, and the message names the setting.checkmethod compares the client's own address with these lists before anything else. A client inSWWAF_ALLOW_NETSskipsSWWAF_DENY_NETS, the country lists and the rate limits, and its country is not looked up. A client inSWWAF_DENY_NETSis refused with403before its body is read and before the lookup. The request is logged asdeniedand not counted for the rate limits. The rate limits neither count nor refuse a client inSWWAF_RATE_LIMIT_EXEMPT_NETS, but the country lists still apply to it.SWWAF_EXCLUSIVELY_ALLOWED_COUNTRIESnow refuses a private, loopback or link-local client unlessSWWAF_ALLOW_NETSlists it.SWWAF_DENIED_COUNTRIESstill lets such a client through, and its address still never goes to GeoJS.README.mddocuments all of this.Not visible in the diff: the lists match single addresses, but the rate limits count an IPv6 client by its /64. The tests use that to show that a denied or exempt request is not counted.
SWWAF_ALLOW_NETSandSWWAF_DENY_NETSis let through, becauseSPEC.mdchecks the allow list first.SWWAF_ALLOW_NETSclients are still held to the size and time limits, whichSPEC.mdapplies to every request.Model: opus-5-5
Review failed: one finding.
internal/proxy/staticlists_test.go,TestAllowNetsSkipEveryCheckButTheSizeLimit: no test shows that a request from a client inSWWAF_ALLOW_NETSis left out of the rate limits' counts. The test shows only that such a client is not refused. If the code counted these requests, an unlisted address in the same IPv6 /64 could be pushed over a limit, and every test would still pass. A likely place for that to break is the later work that counts allowed clients for anomaly alerts. Acceptable: a case like the ones forSWWAF_DENY_NETSandSWWAF_RATE_LIMIT_EXEMPT_NETS, where an allowed address sends requests over the limit and an unlisted address in its /64 still gets its full allowance.Judgement calls accepted: an address in both
SWWAF_ALLOW_NETSandSWWAF_DENY_NETSis let through;SWWAF_ALLOW_NETSclients are still held to the size and time limits.Model: opus-5-5
c6070bf792toe001f1c830Added a test in which an address in
SWWAF_ALLOW_NETSsends requests over the limit and an unlisted address in its IPv6 /64 still gets its full allowance; reworded the doc comment onwantAnswers.Model: opus-5-5
Review passed.
SWWAF_ALLOW_NETSandSWWAF_DENY_NETSis let through.SWWAF_ALLOW_NETSare still held to the size and time limits.Model: opus-5-5