check / check (push) Waiting to run
SWWAF_CROWDSEC_LAPI_URL and SWWAF_CROWDSEC_LAPI_KEY name an engine whose decision list, <url>/v1/decisions, is fetched every minute with the key in X-Api-Key, following no redirect, and kept as a blocklist is: used while a fetch fails, and across restarts through reputation.json. Ban decisions on an Ip or a Range end at the fetch time plus their duration. A listed client's request is refused and bans its netblock with the cause crowdsec until the decision ends; bans.json, ban notes and metrics take the cause. Judgement call: fetched every minute, not a setting. Judgement call: a crowdsec ban never lengthens a limit ban. Judgement call: a lifted crowdsec ban is remade while its decision lasts. Model: opus-5-5
35 lines
965 B
Go
35 lines
965 B
Go
package reputation
|
|
|
|
import (
|
|
"context"
|
|
"net"
|
|
"net/http"
|
|
"net/netip"
|
|
)
|
|
|
|
// SetTransport has l's fetches go through transport instead of the
|
|
// network.
|
|
func (l *Lists) SetTransport(transport http.RoundTripper) {
|
|
l.httpClient.Transport = transport
|
|
l.crowdSecClient.Transport = transport
|
|
}
|
|
|
|
// SetTransport has a's checks go through transport instead of the
|
|
// network.
|
|
func (a *AbuseIPDB) SetTransport(transport http.RoundTripper) {
|
|
a.httpClient.Transport = transport
|
|
}
|
|
|
|
// SetDial has d's queries go through dial instead of the network.
|
|
func (d *DNSBL) SetDial(
|
|
dial func(ctx context.Context, network, address string) (net.Conn, error),
|
|
) {
|
|
d.resolver = &net.Resolver{PreferGo: true, Dial: dial}
|
|
}
|
|
|
|
// LookUp asks zone about addr at once, as a query in the background does,
|
|
// and returns whether zone lists addr.
|
|
func (d *DNSBL) LookUp(zone string, addr netip.Addr) (bool, error) {
|
|
return d.lookUp(context.Background(), query{zone: zone, client: addr})
|
|
}
|