check / check (push) Successful in 3m21s
GET /_smallwebwaf/metrics answers in the Prometheus text format for a request carrying SWWAF_METRICS_TOKEN, 401 without it and 404 while it is unset. Every request under /_smallwebwaf/ but the health check now goes through the checks and is answered where it would be forwarded, 404 for any path but the metrics, so none reaches the app. In the client's history a 401 counts as refused, the metrics and the 404s as neither. SWWAF_METRICS_TOP_N bounds the series by country, the rest counted as other. Deviation: go.mod and go.sum written by hand, as go runs only through make. Deviation: no metrics yet for state files read again after an edit or edits set aside; that work is not merged. Model: opus-5-5
44 lines
1.3 KiB
Go
44 lines
1.3 KiB
Go
package proxy
|
|
|
|
import (
|
|
"crypto/subtle"
|
|
"net/http"
|
|
"strings"
|
|
|
|
"sneak.berlin/go/smallwebwaf/internal/requestlog"
|
|
)
|
|
|
|
// answerAdmin answers a request for smallwebwaf itself, under
|
|
// /_smallwebwaf/, once it has passed the checks: GET MetricsPath with
|
|
// SWWAF_METRICS_TOKEN gets the metrics, and without it is refused with
|
|
// 401. Any other request gets 404, as the metrics do while
|
|
// SWWAF_METRICS_TOKEN is unset.
|
|
func (rq *request) answerAdmin() {
|
|
rq.line.Action = requestlog.ActionAdmin
|
|
rq.startClientResponseTimeout()
|
|
|
|
token := rq.h.config.MetricsToken
|
|
|
|
switch {
|
|
case token == "" || rq.in.Method != http.MethodGet || rq.in.URL.Path != MetricsPath:
|
|
http.Error(rq.out, http.StatusText(http.StatusNotFound), http.StatusNotFound)
|
|
case !hasToken(rq.in, token):
|
|
rq.out.Header().Set("WWW-Authenticate", "Bearer")
|
|
rq.answer(refusal{
|
|
status: http.StatusUnauthorized,
|
|
action: requestlog.ActionAdmin,
|
|
})
|
|
default:
|
|
rq.h.metrics.ServeHTTP(rq.out, rq.in)
|
|
}
|
|
}
|
|
|
|
// hasToken reports whether r carries token, as Authorization: Bearer
|
|
// <token>.
|
|
func hasToken(r *http.Request, token string) bool {
|
|
scheme, sent, _ := strings.Cut(r.Header.Get("Authorization"), " ")
|
|
|
|
return strings.EqualFold(scheme, "Bearer") &&
|
|
subtle.ConstantTimeCompare([]byte(sent), []byte(token)) == 1
|
|
}
|