mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-04 15:06:37 +08:00
[优化] 白名单优先级高于黑名单
This commit is contained in:
@@ -699,6 +699,18 @@ func TestManagedPowLuaFilesUseInternalChallengeFlow(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestManagedWAFLuaTreatsWhitelistAsAllowlist(t *testing.T) {
|
||||
if !strings.Contains(openRestyWAFRuntimeLua, "local function first_allowlist_group(groups)") {
|
||||
t.Fatal("expected waf runtime to detect allowlist rule groups")
|
||||
}
|
||||
if !strings.Contains(openRestyWAFRuntimeLua, "local allowlist_group = first_allowlist_group(groups)") {
|
||||
t.Fatal("expected waf runtime to enter allowlist mode when whitelist rules exist")
|
||||
}
|
||||
if !strings.Contains(openRestyWAFRuntimeLua, "return exit_with_group(allowlist_group)") {
|
||||
t.Fatal("expected waf runtime to block requests that miss configured whitelists")
|
||||
}
|
||||
}
|
||||
|
||||
func TestManagerRollbackRestoresCertFiles(t *testing.T) {
|
||||
tempDir := t.TempDir()
|
||||
routePath := filepath.Join(tempDir, "routes.conf")
|
||||
|
||||
@@ -91,6 +91,10 @@ local function list_contains(items, value)
|
||||
return false
|
||||
end
|
||||
|
||||
local function table_has_items(items)
|
||||
return type(items) == "table" and #items > 0
|
||||
end
|
||||
|
||||
local function parse_ipv4(value)
|
||||
local a, b, c, d = string.match(value or "", "^(%d+)%.(%d+)%.(%d+)%.(%d+)$")
|
||||
if not a then
|
||||
@@ -215,6 +219,17 @@ local function exit_with_group(group)
|
||||
return ngx.exit(ngx.status)
|
||||
end
|
||||
|
||||
local function first_allowlist_group(groups)
|
||||
for _, group in ipairs(groups) do
|
||||
if table_has_items(group.ip_whitelist)
|
||||
or table_has_items(group.ip_whitelist_group_ids)
|
||||
or table_has_items(group.country_whitelist) then
|
||||
return group
|
||||
end
|
||||
end
|
||||
return nil
|
||||
end
|
||||
|
||||
local config = load_config()
|
||||
if not config then
|
||||
if config_dict:add("_missing_config_logged", true, 60) then
|
||||
@@ -249,6 +264,11 @@ for _, group in ipairs(groups) do
|
||||
end
|
||||
end
|
||||
|
||||
local allowlist_group = first_allowlist_group(groups)
|
||||
if allowlist_group then
|
||||
return exit_with_group(allowlist_group)
|
||||
end
|
||||
|
||||
for _, group in ipairs(groups) do
|
||||
if ip_matches(group.ip_blacklist, ip) or ip_matches_group_ids(group.ip_blacklist_group_ids, ip, ip_groups_config) then
|
||||
return exit_with_group(group)
|
||||
|
||||
Reference in New Issue
Block a user