mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-11 09:46:37 +08:00
migrate
This commit is contained in:
@@ -0,0 +1,9 @@
|
||||
// Copyright 2026 Arctel.net
|
||||
// SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
package waf
|
||||
|
||||
const (
|
||||
errWAFRuleGroupNotFound = "WAF 规则组不存在"
|
||||
errWAFIPGroupNotFound = "IP 组不存在"
|
||||
)
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,67 @@
|
||||
// Copyright 2026 Arctel.net
|
||||
// SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
package waf
|
||||
|
||||
import (
|
||||
"context"
|
||||
"testing"
|
||||
|
||||
"github.com/Rain-kl/Wavelet/internal/db"
|
||||
"github.com/Rain-kl/Wavelet/internal/model"
|
||||
"github.com/glebarez/sqlite"
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
"gorm.io/gorm"
|
||||
)
|
||||
|
||||
func setupWAFTestDB(t *testing.T) func() {
|
||||
t.Helper()
|
||||
|
||||
sqliteDB, err := gorm.Open(sqlite.Open(":memory:"), &gorm.Config{
|
||||
DisableForeignKeyConstraintWhenMigrating: true,
|
||||
})
|
||||
require.NoError(t, err)
|
||||
require.NoError(t, sqliteDB.AutoMigrate(
|
||||
&model.OpenFlareWAFRuleGroup{},
|
||||
&model.OpenFlareWAFIPGroup{},
|
||||
&model.OpenFlareWAFRuleGroupBinding{},
|
||||
))
|
||||
|
||||
db.SetDB(sqliteDB)
|
||||
return func() {
|
||||
db.SetDB(nil)
|
||||
}
|
||||
}
|
||||
|
||||
func TestCreateRuleGroup(t *testing.T) {
|
||||
cleanup := setupWAFTestDB(t)
|
||||
defer cleanup()
|
||||
ctx := context.Background()
|
||||
|
||||
group, err := CreateRuleGroup(ctx, RuleGroupInput{
|
||||
Name: "edge guard",
|
||||
Enabled: true,
|
||||
BlockStatusCode: 451,
|
||||
IPWhitelist: []string{" 192.0.2.1 ", "192.0.2.1", "198.51.100.0/24"},
|
||||
IPBlacklist: []string{"203.0.113.10"},
|
||||
CountryBlacklist: []string{" cn ", "CN", "us"},
|
||||
})
|
||||
require.NoError(t, err)
|
||||
assert.NotZero(t, group.ID)
|
||||
assert.False(t, group.IsGlobal)
|
||||
assert.Equal(t, "edge guard", group.Name)
|
||||
require.Len(t, group.IPWhitelist, 2)
|
||||
assert.Equal(t, "192.0.2.1", group.IPWhitelist[0])
|
||||
assert.Equal(t, "198.51.100.0/24", group.IPWhitelist[1])
|
||||
require.Len(t, group.CountryBlacklist, 2)
|
||||
assert.Equal(t, "CN", group.CountryBlacklist[0])
|
||||
assert.Equal(t, "US", group.CountryBlacklist[1])
|
||||
|
||||
_, err = CreateRuleGroup(ctx, RuleGroupInput{
|
||||
Name: "bad ip",
|
||||
Enabled: true,
|
||||
IPBlacklist: []string{"not-an-ip"},
|
||||
})
|
||||
require.Error(t, err)
|
||||
}
|
||||
@@ -0,0 +1,240 @@
|
||||
// Copyright 2026 Arctel.net
|
||||
// SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
package waf
|
||||
|
||||
import (
|
||||
"errors"
|
||||
"strconv"
|
||||
|
||||
"github.com/Rain-kl/Wavelet/internal/apps/openflare/compat"
|
||||
"github.com/gin-gonic/gin"
|
||||
"gorm.io/gorm"
|
||||
)
|
||||
|
||||
func handleLogicError(c *gin.Context, err error) bool {
|
||||
if err == nil {
|
||||
return false
|
||||
}
|
||||
if errors.Is(err, gorm.ErrRecordNotFound) {
|
||||
compat.Fail(c, "记录不存在")
|
||||
return true
|
||||
}
|
||||
compat.Fail(c, err.Error())
|
||||
return true
|
||||
}
|
||||
|
||||
func routeIDParam(c *gin.Context) (uint, bool) {
|
||||
raw := c.Param("route_id")
|
||||
if raw == "" {
|
||||
compat.Fail(c, "invalid id")
|
||||
return 0, false
|
||||
}
|
||||
id64, err := strconv.ParseUint(raw, 10, 64)
|
||||
if err != nil || id64 == 0 {
|
||||
compat.Fail(c, "invalid id")
|
||||
return 0, false
|
||||
}
|
||||
return uint(id64), true
|
||||
}
|
||||
|
||||
// ListRuleGroupsHandler lists all WAF rule groups.
|
||||
func ListRuleGroupsHandler(c *gin.Context) {
|
||||
groups, err := ListRuleGroups(c.Request.Context())
|
||||
if handleLogicError(c, err) {
|
||||
return
|
||||
}
|
||||
compat.OK(c, groups)
|
||||
}
|
||||
|
||||
// GetRuleGroupHandler returns a WAF rule group by id.
|
||||
func GetRuleGroupHandler(c *gin.Context) {
|
||||
id, ok := compat.IDParam(c)
|
||||
if !ok {
|
||||
return
|
||||
}
|
||||
group, err := GetRuleGroup(c.Request.Context(), id)
|
||||
if handleLogicError(c, err) {
|
||||
return
|
||||
}
|
||||
compat.OK(c, group)
|
||||
}
|
||||
|
||||
// CreateRuleGroupHandler creates a WAF rule group.
|
||||
func CreateRuleGroupHandler(c *gin.Context) {
|
||||
var input RuleGroupInput
|
||||
if !compat.BindJSON(c, &input) {
|
||||
return
|
||||
}
|
||||
group, err := CreateRuleGroup(c.Request.Context(), input)
|
||||
if handleLogicError(c, err) {
|
||||
return
|
||||
}
|
||||
compat.OK(c, group)
|
||||
}
|
||||
|
||||
// UpdateRuleGroupHandler updates a WAF rule group.
|
||||
func UpdateRuleGroupHandler(c *gin.Context) {
|
||||
id, ok := compat.IDParam(c)
|
||||
if !ok {
|
||||
return
|
||||
}
|
||||
var input RuleGroupInput
|
||||
if !compat.BindJSON(c, &input) {
|
||||
return
|
||||
}
|
||||
group, err := UpdateRuleGroup(c.Request.Context(), id, input)
|
||||
if handleLogicError(c, err) {
|
||||
return
|
||||
}
|
||||
compat.OK(c, group)
|
||||
}
|
||||
|
||||
// DeleteRuleGroupHandler deletes a WAF rule group.
|
||||
func DeleteRuleGroupHandler(c *gin.Context) {
|
||||
id, ok := compat.IDParam(c)
|
||||
if !ok {
|
||||
return
|
||||
}
|
||||
if err := DeleteRuleGroup(c.Request.Context(), id); handleLogicError(c, err) {
|
||||
return
|
||||
}
|
||||
compat.OKMessage(c, "")
|
||||
}
|
||||
|
||||
// ReplaceRuleGroupSitesHandler replaces site bindings for a rule group.
|
||||
func ReplaceRuleGroupSitesHandler(c *gin.Context) {
|
||||
id, ok := compat.IDParam(c)
|
||||
if !ok {
|
||||
return
|
||||
}
|
||||
var request IDsRequest
|
||||
if !compat.BindJSON(c, &request) {
|
||||
return
|
||||
}
|
||||
group, err := ReplaceRuleGroupSites(c.Request.Context(), id, request.IDs)
|
||||
if handleLogicError(c, err) {
|
||||
return
|
||||
}
|
||||
compat.OK(c, group)
|
||||
}
|
||||
|
||||
// GetSiteRuleGroupsHandler returns WAF rule groups for a proxy route.
|
||||
func GetSiteRuleGroupsHandler(c *gin.Context) {
|
||||
routeID, ok := routeIDParam(c)
|
||||
if !ok {
|
||||
return
|
||||
}
|
||||
view, err := GetSiteRuleGroups(c.Request.Context(), routeID)
|
||||
if handleLogicError(c, err) {
|
||||
return
|
||||
}
|
||||
compat.OK(c, view)
|
||||
}
|
||||
|
||||
// ReplaceSiteRuleGroupsHandler replaces rule group bindings for a proxy route.
|
||||
func ReplaceSiteRuleGroupsHandler(c *gin.Context) {
|
||||
routeID, ok := routeIDParam(c)
|
||||
if !ok {
|
||||
return
|
||||
}
|
||||
var request IDsRequest
|
||||
if !compat.BindJSON(c, &request) {
|
||||
return
|
||||
}
|
||||
view, err := ReplaceSiteRuleGroups(c.Request.Context(), routeID, request.IDs)
|
||||
if handleLogicError(c, err) {
|
||||
return
|
||||
}
|
||||
compat.OK(c, view)
|
||||
}
|
||||
|
||||
// ListIPGroupsHandler lists all WAF IP groups.
|
||||
func ListIPGroupsHandler(c *gin.Context) {
|
||||
groups, err := ListIPGroups(c.Request.Context())
|
||||
if handleLogicError(c, err) {
|
||||
return
|
||||
}
|
||||
compat.OK(c, groups)
|
||||
}
|
||||
|
||||
// GetIPGroupHandler returns a WAF IP group by id.
|
||||
func GetIPGroupHandler(c *gin.Context) {
|
||||
id, ok := compat.IDParam(c)
|
||||
if !ok {
|
||||
return
|
||||
}
|
||||
group, err := GetIPGroup(c.Request.Context(), id)
|
||||
if handleLogicError(c, err) {
|
||||
return
|
||||
}
|
||||
compat.OK(c, group)
|
||||
}
|
||||
|
||||
// CreateIPGroupHandler creates a WAF IP group.
|
||||
func CreateIPGroupHandler(c *gin.Context) {
|
||||
var input IPGroupInput
|
||||
if !compat.BindJSON(c, &input) {
|
||||
return
|
||||
}
|
||||
group, err := CreateIPGroup(c.Request.Context(), input)
|
||||
if handleLogicError(c, err) {
|
||||
return
|
||||
}
|
||||
compat.OK(c, group)
|
||||
}
|
||||
|
||||
// UpdateIPGroupHandler updates a WAF IP group.
|
||||
func UpdateIPGroupHandler(c *gin.Context) {
|
||||
id, ok := compat.IDParam(c)
|
||||
if !ok {
|
||||
return
|
||||
}
|
||||
var input IPGroupInput
|
||||
if !compat.BindJSON(c, &input) {
|
||||
return
|
||||
}
|
||||
group, err := UpdateIPGroup(c.Request.Context(), id, input)
|
||||
if handleLogicError(c, err) {
|
||||
return
|
||||
}
|
||||
compat.OK(c, group)
|
||||
}
|
||||
|
||||
// DeleteIPGroupHandler deletes a WAF IP group.
|
||||
func DeleteIPGroupHandler(c *gin.Context) {
|
||||
id, ok := compat.IDParam(c)
|
||||
if !ok {
|
||||
return
|
||||
}
|
||||
if err := DeleteIPGroup(c.Request.Context(), id); handleLogicError(c, err) {
|
||||
return
|
||||
}
|
||||
compat.OKMessage(c, "")
|
||||
}
|
||||
|
||||
// SyncIPGroupHandler triggers a stub sync for a WAF IP group.
|
||||
func SyncIPGroupHandler(c *gin.Context) {
|
||||
id, ok := compat.IDParam(c)
|
||||
if !ok {
|
||||
return
|
||||
}
|
||||
result, err := SyncIPGroup(c.Request.Context(), id)
|
||||
if handleLogicError(c, err) {
|
||||
return
|
||||
}
|
||||
compat.OK(c, result)
|
||||
}
|
||||
|
||||
// TestIPGroupAutoConfigHandler tests automatic IP group configuration (stub).
|
||||
func TestIPGroupAutoConfigHandler(c *gin.Context) {
|
||||
var input IPGroupAutoTestInput
|
||||
if !compat.BindJSON(c, &input) {
|
||||
return
|
||||
}
|
||||
result, err := TestIPGroupAutoConfig(c.Request.Context(), input)
|
||||
if handleLogicError(c, err) {
|
||||
return
|
||||
}
|
||||
compat.OK(c, result)
|
||||
}
|
||||
Reference in New Issue
Block a user