check / check (push) Successful in 3m47s
Adds SWWAF_ALLOW_NETS, SWWAF_RATE_LIMIT_EXEMPT_NETS and SWWAF_DENY_NETS, read like SWWAF_TRUSTED_PROXIES and empty by default, and checked against the client's own address before its country is looked up. A client in SWWAF_ALLOW_NETS skips the country lists and the rate limits and is not looked up. One in SWWAF_DENY_NETS is refused with 403, logged as denied and not counted. One in SWWAF_RATE_LIMIT_EXEMPT_NETS is neither counted nor refused by the rate limits. SWWAF_EXCLUSIVELY_ALLOWED_COUNTRIES now refuses a private, loopback or link-local client unless SWWAF_ALLOW_NETS lists it. Judgement call: an address in both SWWAF_ALLOW_NETS and SWWAF_DENY_NETS is let through. Judgement call: the size and time limits still apply to SWWAF_ALLOW_NETS. Model: opus-5-5
42 lines
1.1 KiB
Go
42 lines
1.1 KiB
Go
package proxy
|
|
|
|
import (
|
|
"context"
|
|
"net/netip"
|
|
"slices"
|
|
)
|
|
|
|
// countryDenied reports whether the country lists refuse the request.
|
|
// The client's country is looked up only while a list is set, and never
|
|
// for a client on a private, loopback or link-local address, which has
|
|
// no country. A client without a country, or whose country cannot be
|
|
// found, is refused only by SWWAF_EXCLUSIVELY_ALLOWED_COUNTRIES. ctx is
|
|
// the request's own context.
|
|
func (rq *request) countryDenied(ctx context.Context) bool {
|
|
denied := rq.h.config.DeniedCountries
|
|
allowed := rq.h.config.ExclusivelyAllowedCountries
|
|
|
|
if len(denied) == 0 && len(allowed) == 0 {
|
|
return false
|
|
}
|
|
|
|
var country string
|
|
if hasCountry(rq.client) {
|
|
country = rq.h.geojs.Country(ctx, clientGroup(rq.client))
|
|
}
|
|
|
|
rq.line.Country = country
|
|
|
|
if slices.Contains(denied, country) {
|
|
return true
|
|
}
|
|
|
|
return len(allowed) > 0 && !slices.Contains(allowed, country)
|
|
}
|
|
|
|
// hasCountry reports whether addr can be placed in a country: private,
|
|
// loopback and link-local addresses cannot.
|
|
func hasCountry(addr netip.Addr) bool {
|
|
return !addr.IsPrivate() && !addr.IsLoopback() && !addr.IsLinkLocalUnicast()
|
|
}
|