package proxy import ( "context" "net/netip" "slices" ) // countryDenied reports whether the country lists refuse the request. // The client's country is looked up only while a list is set, and never // for a client on a private, loopback or link-local address, which has // no country. A client without a country, or whose country cannot be // found, is refused only by SWWAF_EXCLUSIVELY_ALLOWED_COUNTRIES. ctx is // the request's own context. func (rq *request) countryDenied(ctx context.Context) bool { denied := rq.h.config.DeniedCountries allowed := rq.h.config.ExclusivelyAllowedCountries if len(denied) == 0 && len(allowed) == 0 { return false } var country string if hasCountry(rq.client) { country = rq.h.geojs.Country(ctx, clientGroup(rq.client)) } rq.line.Country = country if slices.Contains(denied, country) { return true } return len(allowed) > 0 && !slices.Contains(allowed, country) } // hasCountry reports whether addr can be placed in a country: private, // loopback and link-local addresses cannot. func hasCountry(addr netip.Addr) bool { return !addr.IsPrivate() && !addr.IsLoopback() && !addr.IsLinkLocalUnicast() }