diff --git a/openflare_agent/internal/nginx/waf_assets.go b/openflare_agent/internal/nginx/waf_assets.go index db9415ec..4426e165 100644 --- a/openflare_agent/internal/nginx/waf_assets.go +++ b/openflare_agent/internal/nginx/waf_assets.go @@ -50,7 +50,7 @@ local function load_config() end local function list_contains(items, value) - if not items or not value or value == "" then + if not items or type(items) ~= "table" or not value or value == "" then return false end for _, item in ipairs(items) do @@ -95,7 +95,7 @@ local function ipv4_in_cidr(ip, cidr) end local function ip_matches(items, ip) - if not items or not ip or ip == "" then + if not items or type(items) ~= "table" or not ip or ip == "" then return false end for _, item in ipairs(items) do @@ -196,7 +196,7 @@ end local country = nil for _, group in ipairs(groups) do - if group.country_whitelist and #group.country_whitelist > 0 then + if type(group.country_whitelist) == "table" and #group.country_whitelist > 0 then country = country or lookup_country(ip) if list_contains(group.country_whitelist, country) then return @@ -211,7 +211,7 @@ for _, group in ipairs(groups) do end for _, group in ipairs(groups) do - if group.country_blacklist and #group.country_blacklist > 0 then + if type(group.country_blacklist) == "table" and #group.country_blacklist > 0 then country = country or lookup_country(ip) if list_contains(group.country_blacklist, country) then return exit_with_group(group) diff --git a/openflare_server/utils/render/openresty/render.go b/openflare_server/utils/render/openresty/render.go index 8adab7d6..5abc57d5 100644 --- a/openflare_server/utils/render/openresty/render.go +++ b/openflare_server/utils/render/openresty/render.go @@ -336,7 +336,7 @@ func renderOpenRestyLimitZoneBlock() string { } func renderOpenRestyObservabilityTemplateBlock() string { - return fmt.Sprintf(" log_by_lua_file %s/log.lua;\n lua_shared_dict openflare_pow_challenges 10m;\n lua_shared_dict openflare_pow_sessions 10m;\n lua_shared_dict openflare_pow_config 1m;\n lua_shared_dict openflare_waf_config 1m;\n\n server {\n listen %s;\n server_name openflare-observability;\n access_log off;\n\n location = /openflare/stub_status {\n stub_status;\n }\n\n location = /openflare/observability {\n content_by_lua_file %s/observability.lua;\n }\n }\n\n", LuaDirPlaceholder, ObservabilityListenPlaceholder, LuaDirPlaceholder) + return fmt.Sprintf(" lua_shared_dict openflare_observability 10m;\n lua_shared_dict openflare_pow_challenges 10m;\n lua_shared_dict openflare_pow_sessions 10m;\n lua_shared_dict openflare_pow_config 1m;\n lua_shared_dict openflare_waf_config 1m;\n init_worker_by_lua_file %s/observability/init.lua;\n log_by_lua_file %s/observability/log.lua;\n\n server {\n listen %s;\n server_name openflare-observability;\n access_log off;\n\n location = /openflare/stub_status {\n stub_status;\n }\n\n location = /openflare/observability {\n default_type application/json;\n content_by_lua_file %s/observability/read.lua;\n }\n }\n\n", LuaDirPlaceholder, LuaDirPlaceholder, ObservabilityListenPlaceholder, LuaDirPlaceholder) } func renderHTTPProxyServer(serverNames string, siteName string, originURL string, originHost string, customHeaders []CustomHeader, cacheConfig routeCacheConfig, limitConfig routeLimitConfig, upstreamConfig routeUpstreamConfig, powEnabled bool, basicAuthEnabled bool, basicAuthUsername string, basicAuthPassword string, cfg ConfigSnapshot) string {