diff --git a/openflare_agent/internal/nginx/pow_assets.go b/openflare_agent/internal/nginx/pow_assets.go index 31d2eeda..2ff116ff 100644 --- a/openflare_agent/internal/nginx/pow_assets.go +++ b/openflare_agent/internal/nginx/pow_assets.go @@ -17,7 +17,7 @@ local source = debug.getinfo(1, "S").source or "" if string.sub(source, 1, 1) == "@" then local script_path = string.sub(source, 2) local base_dir = string.match(script_path, "^(.*)/pow/[^/]+%.lua$") - if base_dir and base_dir ~= "" then + if base_dir and base_dir ~= "" and not string.find(package.path, base_dir, 1, true) then package.path = base_dir .. "/?.lua;" .. base_dir .. "/?/init.lua;" .. package.path end end @@ -170,7 +170,7 @@ const openRestyPowCheckLua = `local source = debug.getinfo(1, "S").source or "" if string.sub(source, 1, 1) == "@" then local script_path = string.sub(source, 2) local base_dir = string.match(script_path, "^(.*)/pow/[^/]+%.lua$") - if base_dir and base_dir ~= "" then + if base_dir and base_dir ~= "" and not string.find(package.path, base_dir, 1, true) then package.path = base_dir .. "/?.lua;" .. base_dir .. "/?/init.lua;" .. package.path end end diff --git a/openflare_agent/internal/nginx/waf_assets.go b/openflare_agent/internal/nginx/waf_assets.go index 6f909629..db9415ec 100644 --- a/openflare_agent/internal/nginx/waf_assets.go +++ b/openflare_agent/internal/nginx/waf_assets.go @@ -229,7 +229,7 @@ const openRestyWAFCheckLua = `local source = debug.getinfo(1, "S").source or "" if string.sub(source, 1, 1) == "@" then local script_path = string.sub(source, 2) local base_dir = string.match(script_path, "^(.*)/waf/[^/]+%.lua$") - if base_dir and base_dir ~= "" then + if base_dir and base_dir ~= "" and not string.find(package.path, base_dir, 1, true) then package.path = base_dir .. "/?.lua;" .. base_dir .. "/?/init.lua;" .. package.path end end diff --git a/openflare_server/service/https_phase1_test.go b/openflare_server/service/https_phase1_test.go index 598bca07..a12937f9 100644 --- a/openflare_server/service/https_phase1_test.go +++ b/openflare_server/service/https_phase1_test.go @@ -1025,7 +1025,7 @@ func TestPublishConfigVersionDetectsPoWChanges(t *testing.T) { if !strings.Contains(secondRelease.Version.RenderedConfig, "application/javascript js mjs;") { t.Fatal("expected rendered config to serve Anubis module scripts with a JavaScript MIME type") } - if !strings.Contains(secondRelease.Version.RenderedConfig, " package.path = \"__OPENFLARE_LUA_DIR__/?.lua;__OPENFLARE_LUA_DIR__/?/init.lua;\" .. package.path\n require(\"waf.runtime\").check()\n if ngx.ctx.openflare_waf_blocked then\n return\n end\n require(\"pow.runtime\").check()") { + if !strings.Contains(secondRelease.Version.RenderedConfig, " if not string.find(package.path, \"__OPENFLARE_LUA_DIR__/?.lua\", 1, true) then\n package.path = \"__OPENFLARE_LUA_DIR__/?.lua;__OPENFLARE_LUA_DIR__/?/init.lua;\" .. package.path\n end\n require(\"waf.runtime\").check()\n if ngx.ctx.openflare_waf_blocked then\n return\n end\n require(\"pow.runtime\").check()") { t.Fatal("expected combined WAF and PoW access handler to short-circuit before PoW") } locationStart := strings.Index(secondRelease.Version.RenderedConfig, " location / {\n") diff --git a/openflare_server/utils/render/openresty/render.go b/openflare_server/utils/render/openresty/render.go index 5845e0c4..bdb5521d 100644 --- a/openflare_server/utils/render/openresty/render.go +++ b/openflare_server/utils/render/openresty/render.go @@ -387,14 +387,16 @@ func renderAccessBlock(siteName string, powEnabled bool) string { } return fmt.Sprintf(` set $openflare_waf_site "%s"; access_by_lua_block { - package.path = "%s/?.lua;%s/?/init.lua;" .. package.path + if not string.find(package.path, "%s/?.lua", 1, true) then + package.path = "%s/?.lua;%s/?/init.lua;" .. package.path + end require("waf.runtime").check() if ngx.ctx.openflare_waf_blocked then return end require("pow.runtime").check() } -`, escapedSiteName, LuaDirPlaceholder, LuaDirPlaceholder) +`, escapedSiteName, LuaDirPlaceholder, LuaDirPlaceholder, LuaDirPlaceholder) } func renderBasicAuthBlock(enabled bool, username, password string) string {