mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-05 07:26:36 +08:00
前端优化
This commit is contained in:
@@ -695,6 +695,11 @@ func buildIPGroup(group *model.OpenFlareWAFIPGroup, input IPGroupInput) (*model.
|
||||
group.Type = groupType
|
||||
group.Enabled = input.Enabled
|
||||
group.IPList = string(ipListJSON)
|
||||
if groupType == wafIPGroupTypeAutomatic {
|
||||
if err := pruneIPGroupExtIPs(group, normalizedIPs); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
}
|
||||
group.AutoConfig = autoConfig
|
||||
group.SubscriptionURL = subscriptionURL
|
||||
group.SubscriptionFormat = subscriptionFormat
|
||||
@@ -785,6 +790,34 @@ func loadIPGroupReferenceCounts(ctx context.Context) (map[uint]int, error) {
|
||||
return counts, nil
|
||||
}
|
||||
|
||||
func pruneIPGroupExtIPs(group *model.OpenFlareWAFIPGroup, ipList []string) error {
|
||||
if group == nil {
|
||||
return nil
|
||||
}
|
||||
allowed := make(map[string]struct{}, len(ipList))
|
||||
for _, ip := range ipList {
|
||||
allowed[ip] = struct{}{}
|
||||
}
|
||||
var extIPs []ipGroupExtIP
|
||||
if group.ExtIPs != "" && group.ExtIPs != "[]" {
|
||||
if err := json.Unmarshal([]byte(group.ExtIPs), &extIPs); err != nil {
|
||||
return err
|
||||
}
|
||||
}
|
||||
pruned := make([]ipGroupExtIP, 0, len(extIPs))
|
||||
for _, extIP := range extIPs {
|
||||
if _, ok := allowed[extIP.IP]; ok {
|
||||
pruned = append(pruned, extIP)
|
||||
}
|
||||
}
|
||||
extIPsJSON, err := json.Marshal(pruned)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
group.ExtIPs = string(extIPsJSON)
|
||||
return nil
|
||||
}
|
||||
|
||||
func normalizeIPList(items []string) ([]string, error) {
|
||||
normalized := make([]string, 0, len(items))
|
||||
for _, raw := range items {
|
||||
|
||||
@@ -65,3 +65,46 @@ func TestCreateRuleGroup(t *testing.T) {
|
||||
})
|
||||
require.Error(t, err)
|
||||
}
|
||||
|
||||
func TestPruneIPGroupExtIPs(t *testing.T) {
|
||||
group := &model.OpenFlareWAFIPGroup{
|
||||
ExtIPs: `[{"ip":"203.0.113.10","captured_at":"2026-06-18T10:00:00Z"},{"ip":"203.0.113.11","captured_at":"2026-06-18T11:00:00Z"}]`,
|
||||
}
|
||||
err := pruneIPGroupExtIPs(group, []string{"203.0.113.10"})
|
||||
require.NoError(t, err)
|
||||
assert.JSONEq(t, `[{"ip":"203.0.113.10","captured_at":"2026-06-18T10:00:00Z"}]`, group.ExtIPs)
|
||||
}
|
||||
|
||||
func TestUpdateIPGroupPrunesAutomaticExtIPs(t *testing.T) {
|
||||
cleanup := setupWAFTestDB(t)
|
||||
defer cleanup()
|
||||
ctx := context.Background()
|
||||
|
||||
created, err := CreateIPGroup(ctx, IPGroupInput{
|
||||
Name: "auto group",
|
||||
Type: wafIPGroupTypeAutomatic,
|
||||
Enabled: true,
|
||||
AutoConfig: []byte(`{"lookback_minutes":60,"ttl":-1,"rules":[{"name":"scan","expr":"request_count > 1"}]}`),
|
||||
})
|
||||
require.NoError(t, err)
|
||||
|
||||
group, err := model.GetOpenFlareWAFIPGroupByID(ctx, created.ID)
|
||||
require.NoError(t, err)
|
||||
group.IPList = `["203.0.113.10","203.0.113.11"]`
|
||||
group.ExtIPs = `[{"ip":"203.0.113.10","captured_at":"2026-06-18T10:00:00Z"},{"ip":"203.0.113.11","captured_at":"2026-06-18T11:00:00Z"}]`
|
||||
require.NoError(t, model.UpdateOpenFlareWAFIPGroup(ctx, group))
|
||||
|
||||
updated, err := UpdateIPGroup(ctx, created.ID, IPGroupInput{
|
||||
Name: created.Name,
|
||||
Type: created.Type,
|
||||
Enabled: created.Enabled,
|
||||
IPList: []string{"203.0.113.10"},
|
||||
AutoConfig: created.AutoConfig,
|
||||
Remark: created.Remark,
|
||||
})
|
||||
require.NoError(t, err)
|
||||
require.Len(t, updated.IPList, 1)
|
||||
assert.Equal(t, "203.0.113.10", updated.IPList[0])
|
||||
require.Len(t, updated.ExtIPs, 1)
|
||||
assert.Equal(t, "203.0.113.10", updated.ExtIPs[0].IP)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user