package proxy import ( "sneak.berlin/go/smallwebwaf/internal/alerts" ) // blocklistDenied notes in the log line the URLs of the blocklists that // list the client, counts each of them in the metrics and raises a // reputation_hit alert for it, and reports whether SWWAF_BLOCKLIST_ACTION, // being deny, refuses the request. Being limit, it lowers the client's // limits instead (see limitPercentages), and being log, it does nothing // more. func (rq *request) blocklistDenied() bool { listedBy := rq.h.lists.ListedBy(rq.client) rq.line.Reputation = listedBy for _, listURL := range listedBy { rq.h.metrics.ReputationHit(listURL) rq.h.alerts.Raise(alerts.Alert{ Event: alerts.EventReputationHit, Client: rq.client, Netblock: clientGroup(rq.client), ASN: rq.line.ASN, ASName: rq.line.ASName, Country: rq.line.Country, Reason: "listed by a blocklist", Detail: map[string]any{"source": listURL}, }) } return len(listedBy) > 0 && rq.h.config.BlocklistAction == "deny" }