From 1bff2dadd41d706f650716a183616e5edbe27125 Mon Sep 17 00:00:00 2001 From: ryan Date: Sat, 30 May 2026 15:12:49 +0800 Subject: [PATCH] =?UTF-8?q?[=E4=BC=98=E5=8C=96]=20=E5=90=88=E5=B9=B6=20WAF?= =?UTF-8?q?=20=E5=92=8C=20PoW=20=E8=AE=BF=E9=97=AE=E5=A4=84=E7=90=86?= =?UTF-8?q?=E9=80=BB=E8=BE=91=EF=BC=8C=E6=9B=B4=E6=96=B0=E7=9B=B8=E5=85=B3?= =?UTF-8?q?=E5=87=BD=E6=95=B0=E4=BB=A5=E6=94=AF=E6=8C=81=E6=96=B0=E7=9A=84?= =?UTF-8?q?=E9=85=8D=E7=BD=AE=E6=A0=BC=E5=BC=8F?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- openflare_server/service/config_version.go | 25 ++++++++++--------- openflare_server/service/https_phase1_test.go | 10 ++++---- 2 files changed, 18 insertions(+), 17 deletions(-) diff --git a/openflare_server/service/config_version.go b/openflare_server/service/config_version.go index a300e237..c70cca45 100644 --- a/openflare_server/service/config_version.go +++ b/openflare_server/service/config_version.go @@ -1257,16 +1257,17 @@ func onOff(value bool) string { const nginxPowStaticDirPlaceholder = "__OPENFLARE_POW_STATIC_DIR__" -func renderPowAccessBlock(powEnabled bool) string { - if !powEnabled { - return "" - } - return fmt.Sprintf(" access_by_lua_file %s/pow/check.lua;\n", nginxLuaDirPlaceholder) -} - -func renderWAFAccessBlock(siteName string) string { +func renderAccessBlock(siteName string, powEnabled bool) string { escapedSiteName := escapeNginxString(siteName) - return fmt.Sprintf(" set $openflare_waf_site \"%s\";\n access_by_lua_file %s/waf/check.lua;\n", escapedSiteName, nginxLuaDirPlaceholder) + if !powEnabled { + return fmt.Sprintf(" set $openflare_waf_site \"%s\";\n access_by_lua_file %s/waf/check.lua;\n", escapedSiteName, nginxLuaDirPlaceholder) + } + return fmt.Sprintf(` set $openflare_waf_site "%s"; + access_by_lua_block { + dofile("%s/waf/check.lua") + dofile("%s/pow/check.lua") + } +`, escapedSiteName, nginxLuaDirPlaceholder, nginxLuaDirPlaceholder) } func renderBasicAuthBlock(enabled bool, username, password string) string { @@ -1426,7 +1427,7 @@ func nextVersionNumber(now time.Time) (string, error) { } func renderHTTPProxyServer(serverNames string, siteName string, originURL string, originHost string, customHeaders []ProxyRouteCustomHeaderInput, cacheConfig routeCacheConfig, limitConfig routeLimitConfig, upstreamConfig routeUpstreamConfig, powEnabled bool, basicAuthEnabled bool, basicAuthUsername string, basicAuthPassword string, cfg openRestyConfigSnapshot) string { - return fmt.Sprintf("server {\n listen 80;\n server_name %s;\n%s%s%s location / {\n%s%s%s%s%s }\n%s}\n\n", serverNames, renderWAFAccessBlock(siteName), renderPowAccessBlock(powEnabled), renderPowLocationBlocks(powEnabled), renderBasicAuthBlock(basicAuthEnabled, basicAuthUsername, basicAuthPassword), renderProxyHeaderBlock(originURL, originHost, customHeaders, upstreamConfig), renderRouteLimitBlock(limitConfig), renderRouteCacheBlock(cacheConfig, cfg), renderProxyPassBlock(originURL, upstreamConfig), renderPowStaticLocationBlock(powEnabled)) + return fmt.Sprintf("server {\n listen 80;\n server_name %s;\n%s%s location / {\n%s%s%s%s%s }\n%s}\n\n", serverNames, renderAccessBlock(siteName, powEnabled), renderPowLocationBlocks(powEnabled), renderBasicAuthBlock(basicAuthEnabled, basicAuthUsername, basicAuthPassword), renderProxyHeaderBlock(originURL, originHost, customHeaders, upstreamConfig), renderRouteLimitBlock(limitConfig), renderRouteCacheBlock(cacheConfig, cfg), renderProxyPassBlock(originURL, upstreamConfig), renderPowStaticLocationBlock(powEnabled)) } func renderHTTPRedirectServer(serverNames string, siteName string) string { @@ -1437,7 +1438,7 @@ func renderHTTPRedirectServer(serverNames string, siteName string) string { func renderHTTPSServer(serverNames string, siteName string, originURL string, originHost string, certificateID uint, customHeaders []ProxyRouteCustomHeaderInput, cacheConfig routeCacheConfig, limitConfig routeLimitConfig, upstreamConfig routeUpstreamConfig, powEnabled bool, basicAuthEnabled bool, basicAuthUsername string, basicAuthPassword string, cfg openRestyConfigSnapshot) string { certPath := fmt.Sprintf("%s/%s", nginxCertDirPlaceholder, certificateCertFileName(certificateID)) keyPath := fmt.Sprintf("%s/%s", nginxCertDirPlaceholder, certificateKeyFileName(certificateID)) - return fmt.Sprintf("server {\n listen 443 ssl;\n http2 on;\n server_name %s;\n ssl_certificate %s;\n ssl_certificate_key %s;\n%s%s%s location / {\n%s%s%s%s%s }\n%s}\n\n", serverNames, certPath, keyPath, renderWAFAccessBlock(siteName), renderPowAccessBlock(powEnabled), renderPowLocationBlocks(powEnabled), renderBasicAuthBlock(basicAuthEnabled, basicAuthUsername, basicAuthPassword), renderProxyHeaderBlock(originURL, originHost, customHeaders, upstreamConfig), renderRouteLimitBlock(limitConfig), renderRouteCacheBlock(cacheConfig, cfg), renderProxyPassBlock(originURL, upstreamConfig), renderPowStaticLocationBlock(powEnabled)) + return fmt.Sprintf("server {\n listen 443 ssl;\n http2 on;\n server_name %s;\n ssl_certificate %s;\n ssl_certificate_key %s;\n%s%s location / {\n%s%s%s%s%s }\n%s}\n\n", serverNames, certPath, keyPath, renderAccessBlock(siteName, powEnabled), renderPowLocationBlocks(powEnabled), renderBasicAuthBlock(basicAuthEnabled, basicAuthUsername, basicAuthPassword), renderProxyHeaderBlock(originURL, originHost, customHeaders, upstreamConfig), renderRouteLimitBlock(limitConfig), renderRouteCacheBlock(cacheConfig, cfg), renderProxyPassBlock(originURL, upstreamConfig), renderPowStaticLocationBlock(powEnabled)) } func renderHTTPSServerWithCertificates(serverNames string, originURL string, originHost string, certificateIDs []uint, customHeaders []ProxyRouteCustomHeaderInput, cacheConfig routeCacheConfig, limitConfig routeLimitConfig, upstreamConfig routeUpstreamConfig, powEnabled bool, basicAuthEnabled bool, basicAuthUsername string, basicAuthPassword string, cfg openRestyConfigSnapshot) string { @@ -1448,7 +1449,7 @@ func renderHTTPSServerWithCertificates(serverNames string, originURL string, ori certificateBlock.WriteString(fmt.Sprintf(" ssl_certificate %s;\n", certPath)) certificateBlock.WriteString(fmt.Sprintf(" ssl_certificate_key %s;\n", keyPath)) } - return fmt.Sprintf("server {\n listen 443 ssl;\n http2 on;\n server_name %s;\n%s%s%s\n location / {\n%s%s%s%s%s }\n%s}\n\n", serverNames, certificateBlock.String(), renderPowAccessBlock(powEnabled), renderPowLocationBlocks(powEnabled), renderBasicAuthBlock(basicAuthEnabled, basicAuthUsername, basicAuthPassword), renderProxyHeaderBlock(originURL, originHost, customHeaders, upstreamConfig), renderRouteLimitBlock(limitConfig), renderRouteCacheBlock(cacheConfig, cfg), renderProxyPassBlock(originURL, upstreamConfig), renderPowStaticLocationBlock(powEnabled)) + return fmt.Sprintf("server {\n listen 443 ssl;\n http2 on;\n server_name %s;\n%s%s%s\n location / {\n%s%s%s%s%s }\n%s}\n\n", serverNames, certificateBlock.String(), renderAccessBlock(serverNames, powEnabled), renderPowLocationBlocks(powEnabled), renderBasicAuthBlock(basicAuthEnabled, basicAuthUsername, basicAuthPassword), renderProxyHeaderBlock(originURL, originHost, customHeaders, upstreamConfig), renderRouteLimitBlock(limitConfig), renderRouteCacheBlock(cacheConfig, cfg), renderProxyPassBlock(originURL, upstreamConfig), renderPowStaticLocationBlock(powEnabled)) } func renderServerNames(domains []string) string { diff --git a/openflare_server/service/https_phase1_test.go b/openflare_server/service/https_phase1_test.go index 94f90a82..f66b4729 100644 --- a/openflare_server/service/https_phase1_test.go +++ b/openflare_server/service/https_phase1_test.go @@ -1025,8 +1025,8 @@ func TestPublishConfigVersionDetectsPoWChanges(t *testing.T) { if !strings.Contains(secondRelease.Version.RenderedConfig, "application/javascript js mjs;") { t.Fatal("expected rendered config to serve Anubis module scripts with a JavaScript MIME type") } - if !strings.Contains(secondRelease.Version.RenderedConfig, " access_by_lua_file __OPENFLARE_LUA_DIR__/pow/check.lua;\n\n location = /.within.website/x/cmd/anubis/api/pass-challenge") { - t.Fatal("expected PoW access handler to render at server scope before PoW locations") + if !strings.Contains(secondRelease.Version.RenderedConfig, " dofile(\"__OPENFLARE_LUA_DIR__/waf/check.lua\")\n dofile(\"__OPENFLARE_LUA_DIR__/pow/check.lua\")") { + t.Fatal("expected combined WAF and PoW access handler to render at server scope") } locationStart := strings.Index(secondRelease.Version.RenderedConfig, " location / {\n") if locationStart < 0 { @@ -1037,8 +1037,8 @@ func TestPublishConfigVersionDetectsPoWChanges(t *testing.T) { t.Fatal("expected rendered config to close root proxy location") } rootLocationBlock := secondRelease.Version.RenderedConfig[locationStart : locationStart+locationEnd] - if strings.Contains(rootLocationBlock, "access_by_lua_file") { - t.Fatal("expected root proxy location to avoid mixing access_by_lua_file with proxy_pass") + if strings.Contains(rootLocationBlock, "access_by_lua") { + t.Fatal("expected root proxy location to avoid mixing access_by_lua with proxy_pass") } if !strings.Contains(secondRelease.Version.SnapshotJSON, `"difficulty":5`) { t.Fatal("expected snapshot to persist PoW config") @@ -1102,7 +1102,7 @@ func TestPublishConfigVersionRendersBasicAuthWithPoW(t *testing.T) { if !strings.Contains(result.Version.RenderedConfig, " return ngx.exit(401)\n end\n }\n") { t.Fatal("expected rendered basic auth Lua block to close the if statement before the nginx block") } - if !strings.Contains(result.Version.RenderedConfig, " access_by_lua_file __OPENFLARE_LUA_DIR__/pow/check.lua;") { + if !strings.Contains(result.Version.RenderedConfig, " dofile(\"__OPENFLARE_LUA_DIR__/pow/check.lua\")") { t.Fatal("expected PoW access handler to remain at server scope") } if !strings.Contains(result.Version.RenderedConfig, "proxy_pass http://backend_xbot_example_com_1;") {