check / check (push) Waiting to run
With SWWAF_ABUSEIPDB_KEY set, a client whose history counts an offence (a broken limit, a ban rule's match or a block rule's refusal, counted by kind) is checked in the background, at most SWWAF_ABUSEIPDB_DAILY_BUDGET checks a day, the count kept in reputation.json. A client, an IPv4 address or an IPv6 /64, is checked by the address it sent from, and its score serves all its addresses. A score at or over SWWAF_ABUSEIPDB_MIN_SCORE is a hit for SWWAF_REPUTATION_ACTION, logged as abuseipdb and alerted with its score. A failure or the used-up budget gives no score and raises source_failure. The key goes only in the Key header. Judgement call: the budget's day is UTC; AbuseIPDB documents no reset time. Judgement call: each check sent spends budget; a minute's pause after a failure. Model: opus-5-5
34 lines
925 B
Go
34 lines
925 B
Go
package reputation
|
|
|
|
import (
|
|
"context"
|
|
"net"
|
|
"net/http"
|
|
"net/netip"
|
|
)
|
|
|
|
// SetTransport has l's fetches go through transport instead of the
|
|
// network.
|
|
func (l *Lists) SetTransport(transport http.RoundTripper) {
|
|
l.httpClient.Transport = transport
|
|
}
|
|
|
|
// SetTransport has a's checks go through transport instead of the
|
|
// network.
|
|
func (a *AbuseIPDB) SetTransport(transport http.RoundTripper) {
|
|
a.httpClient.Transport = transport
|
|
}
|
|
|
|
// SetDial has d's queries go through dial instead of the network.
|
|
func (d *DNSBL) SetDial(
|
|
dial func(ctx context.Context, network, address string) (net.Conn, error),
|
|
) {
|
|
d.resolver = &net.Resolver{PreferGo: true, Dial: dial}
|
|
}
|
|
|
|
// LookUp asks zone about addr at once, as a query in the background does,
|
|
// and returns whether zone lists addr.
|
|
func (d *DNSBL) LookUp(zone string, addr netip.Addr) (bool, error) {
|
|
return d.lookUp(context.Background(), query{zone: zone, client: addr})
|
|
}
|