check / check (push) Waiting to run
SWWAF_ANOMALY_CLIENT_*, _NET_*, _ASN_*, _TOTAL_* and SWWAF_WATCH_* with SWWAF_WATCH_NETS: requests and bytes per minute and per hour, each off by default; with all off, nothing is counted. Otherwise every request but the health check is counted, allow-listed and exempt ones included; a count over its threshold raises an anomaly alert, with a cooldown per scope. At most 20,000 counters, kept in alerts.json. A per-AS-number threshold with lookups off, or a malformed SWWAF_WATCH_NETS, stops the start. A cooldown that has run out is dropped as the hour ends, whatever it held back; the hour's summary gives its repeats. Judgement call: refused requests are counted too. Judgement call: per-client counters are kept in alerts.json, which SPEC.md does not list. Judgement call: a request counts for an AS number only if the lookup answered before it ended. Model: opus-5-5
31 lines
759 B
Go
31 lines
759 B
Go
package proxy
|
|
|
|
import (
|
|
"net/netip"
|
|
"testing"
|
|
|
|
"sneak.berlin/go/smallwebwaf/internal/config"
|
|
)
|
|
|
|
func TestWithEveryAnomalyThresholdOffARequestIsNotCounted(t *testing.T) {
|
|
t.Parallel()
|
|
|
|
// A request from a client looked up through GeoJS, with every anomaly
|
|
// threshold off. Its handler has neither GeoJS's answers nor the
|
|
// anomaly counters, nor a clock, and the request no response: reading
|
|
// any of them to count the request panics.
|
|
rq := &request{
|
|
h: &handler{config: &config.Config{LookupSource: "geojs"}},
|
|
client: netip.MustParseAddr("203.0.113.9"),
|
|
lookedUp: true,
|
|
}
|
|
|
|
defer func() {
|
|
if r := recover(); r != nil {
|
|
t.Errorf("counting the request did work, with every threshold off: %v", r)
|
|
}
|
|
}()
|
|
|
|
rq.countAnomalies()
|
|
}
|