check / check (push) Waiting to run
smallwebwaf watches SWWAF_STATE_DIR with fsnotify and takes in a saved edit of a state file in place of what it held. It tells its own writes from an admin's by the SHA-256 of what it last read or wrote; each write first takes in an edit made since. An edit that does not parse is renamed to <name>.bad at the file's next write. Every ban on a netblock is checked, and the next ban is worked out from the one that ended last. Two metrics count the edits taken in and set aside. README.md says how to add and lift a ban. Judgement call: a broken edit is set aside at the next write, since an editor's file can be read half written. Model: opus-5-5
22 lines
660 B
AMPL
22 lines
660 B
AMPL
module sneak.berlin/go/smallwebwaf
|
|
|
|
go 1.26.0
|
|
|
|
require (
|
|
github.com/fsnotify/fsnotify v1.10.1
|
|
github.com/hashicorp/golang-lru/v2 v2.0.7
|
|
github.com/prometheus/client_golang v1.24.1
|
|
)
|
|
|
|
require (
|
|
github.com/beorn7/perks v1.0.1 // indirect
|
|
github.com/cespare/xxhash/v2 v2.3.0 // indirect
|
|
github.com/kylelemons/godebug v1.1.0 // indirect
|
|
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
|
|
github.com/prometheus/client_model v0.6.2 // indirect
|
|
github.com/prometheus/common v0.70.1 // indirect
|
|
github.com/prometheus/procfs v0.21.1 // indirect
|
|
golang.org/x/sys v0.47.0 // indirect
|
|
google.golang.org/protobuf v1.36.11 // indirect
|
|
)
|