fix: 修复 WAF 规则组保存/绑定网站时报 of_waf_rule_group_bindings_pkey 冲突

This commit is contained in:
ryan
2026-06-20 21:52:33 +08:00
parent 99f6f3231a
commit 117d473c27
11 changed files with 194 additions and 29 deletions
+3 -3
View File
@@ -71,7 +71,7 @@ local function load_pow_config()
local groups = {}
for _, group in ipairs(decoded.rule_groups) do
if group.pow_enabled then
groups[tostring(group.id)] = group.pow_config
groups[tostring(group.id)] = group.pow_config or {}
end
end
-- Build site name to pow_config map
@@ -88,12 +88,12 @@ local function load_pow_config()
if not pow_config then
for _, group in ipairs(decoded.rule_groups) do
if group.is_global and group.pow_enabled then
pow_config = group.pow_config
pow_config = group.pow_config or {}
break
end
end
end
if pow_config then
if pow_config ~= nil then
pow_config_dict:set(site, cjson.encode({enabled = true, config = pow_config}), 0)
domain_keys[#domain_keys+1] = site
end
@@ -177,3 +177,52 @@ func TestBuildSnapshotWAFDocumentUsesNormalizedSiteNames(t *testing.T) {
assert.Contains(t, bundle.RouteConfig, `set $openflare_waf_site "example.com"`)
assert.Contains(t, bundle.RouteConfig, `require("pow.runtime").check()`)
}
func TestBuildCurrentConfigBundleEnablesGlobalPoWWithoutExplicitBinding(t *testing.T) {
cleanup := setupConfigVersionTestDB(t)
defer cleanup()
ctx := context.Background()
route := &model.ProxyRoute{
Domain: "pow-global.example.com",
Domains: `["pow-global.example.com"]`,
OriginURL: "http://origin.example.com:8080",
Upstreams: `["http://origin.example.com:8080"]`,
Enabled: true,
}
require.NoError(t, model.CreateProxyRouteRecord(ctx, route))
require.NoError(t, waf.EnsureDefaultRuleGroup(ctx))
globalGroup, err := model.GetGlobalOpenFlareWAFRuleGroup(ctx)
require.NoError(t, err)
globalGroup.PoWEnabled = true
globalGroup.PoWConfig = `{"difficulty":4,"algorithm":"fast","session_ttl":600,"challenge_ttl":300}`
require.NoError(t, model.UpdateOpenFlareWAFRuleGroup(ctx, globalGroup))
bundle, err := buildCurrentConfigBundle(ctx, true)
require.NoError(t, err)
assert.Contains(t, bundle.RouteConfig, `require("pow.runtime").check()`)
var wafRuntime struct {
RuleGroups []struct {
ID uint `json:"id"`
PoWEnabled bool `json:"pow_enabled"`
PoWConfig *struct {
Difficulty int `json:"difficulty"`
} `json:"pow_config"`
} `json:"rule_groups"`
SiteRuleGroups map[string][]uint `json:"site_rule_groups"`
}
for _, file := range bundle.SupportFiles {
if file.Path != "waf_config.json" {
continue
}
require.NoError(t, json.Unmarshal([]byte(file.Content), &wafRuntime))
}
require.Contains(t, wafRuntime.SiteRuleGroups, "pow-global.example.com")
require.Contains(t, wafRuntime.SiteRuleGroups["pow-global.example.com"], globalGroup.ID)
require.NotEmpty(t, wafRuntime.RuleGroups)
assert.True(t, wafRuntime.RuleGroups[0].PoWEnabled)
require.NotNil(t, wafRuntime.RuleGroups[0].PoWConfig)
assert.Equal(t, 4, wafRuntime.RuleGroups[0].PoWConfig.Difficulty)
}
@@ -308,7 +308,7 @@ func buildSnapshotWAFDocument(ctx context.Context, routes []*model.ProxyRoute) (
RegionWhitelist: view.RegionWhitelist,
RegionBlacklist: view.RegionBlacklist,
PoWEnabled: view.PoWEnabled,
PoWConfig: convertPoWConfig(view.PoWConfig),
PoWConfig: convertPoWConfig(view.PoWEnabled, view.PoWConfig),
})
}
ipGroups, err := buildSnapshotWAFIPGroups(ctx, ruleGroups)
@@ -415,10 +415,14 @@ func decodeIPList(raw string) ([]string, error) {
return items, nil
}
func convertPoWConfig(config *waf.PoWConfig) *openrestyrender.PoWConfig {
if config == nil {
func convertPoWConfig(enabled bool, config *waf.PoWConfig) *openrestyrender.PoWConfig {
if !enabled {
return nil
}
if config == nil {
defaultConfig := openrestyrender.DefaultPoWConfig()
return &defaultConfig
}
return &openrestyrender.PoWConfig{
Difficulty: config.Difficulty,
Algorithm: config.Algorithm,
@@ -102,7 +102,8 @@ func up202606200006(ctx context.Context, tx *sql.Tx) error {
if _, err := tx.ExecContext(ctx, `
SELECT setval(
pg_get_serial_sequence('of_waf_rule_group_bindings', 'id'),
COALESCE((SELECT MAX(id) FROM of_waf_rule_group_bindings), 0)
GREATEST(COALESCE((SELECT MAX(id) FROM of_waf_rule_group_bindings), 0), 1),
COALESCE((SELECT MAX(id) FROM of_waf_rule_group_bindings), 0) > 0
)
`); err != nil {
return fmt.Errorf("sync of_waf_rule_group_bindings sequence failed: %w", err)
@@ -1,7 +1,8 @@
-- +goose Up
SELECT setval(
pg_get_serial_sequence('of_waf_rule_group_bindings', 'id'),
COALESCE((SELECT MAX(id) FROM of_waf_rule_group_bindings), 0)
GREATEST(COALESCE((SELECT MAX(id) FROM of_waf_rule_group_bindings), 0), 1),
COALESCE((SELECT MAX(id) FROM of_waf_rule_group_bindings), 0) > 0
);
-- +goose Down
+2 -1
View File
@@ -319,7 +319,8 @@ func syncWAFBindingIDSequence(tx *gorm.DB) error {
return tx.Exec(`
SELECT setval(
pg_get_serial_sequence('of_waf_rule_group_bindings', 'id'),
COALESCE((SELECT MAX(id) FROM of_waf_rule_group_bindings), 0)
GREATEST(COALESCE((SELECT MAX(id) FROM of_waf_rule_group_bindings), 0), 1),
COALESCE((SELECT MAX(id) FROM of_waf_rule_group_bindings), 0) > 0
)
`).Error
}