package proxy import ( "context" "net/netip" "slices" ) // countryDenied reports whether the country lists refuse the request. // The client's country is looked up only while a list is set, and never // for a client on a private, loopback or link-local address, which has // no country and which neither list checks. A client whose country // cannot be found is refused only by SWWAF_EXCLUSIVELY_ALLOWED_COUNTRIES. // ctx is the request's own context. func (rq *request) countryDenied(ctx context.Context) bool { denied := rq.h.config.DeniedCountries allowed := rq.h.config.ExclusivelyAllowedCountries if len(denied) == 0 && len(allowed) == 0 { return false } if !hasCountry(rq.client) { return false } country := rq.h.geojs.Country(ctx, clientGroup(rq.client)) rq.line.Country = country if slices.Contains(denied, country) { return true } return len(allowed) > 0 && !slices.Contains(allowed, country) } // hasCountry reports whether addr can be placed in a country: private, // loopback and link-local addresses cannot. func hasCountry(addr netip.Addr) bool { return !addr.IsPrivate() && !addr.IsLoopback() && !addr.IsLinkLocalUnicast() }